Security fixes are applied to the latest published version. Unreleased source on the default branch is supported on a best-effort basis.
Report vulnerabilities privately through GitHub Security Advisories.
Include the affected version, environment, reproduction steps, impact, and any suggested mitigation. Do not open a public issue for an undisclosed vulnerability and do not include credentials or other secrets.
You should receive an acknowledgement after the report is reviewed. Publication and remediation timing depend on severity, reproducibility, and release impact.