Security fixes target the latest code on the default branch. Older snapshots and forks are not actively supported.
Please do not open a public issue for a suspected vulnerability.
- Open the repository's Security tab.
- Choose Advisories and Report a vulnerability.
- Include affected files or versions, impact, reproduction steps, and any suggested mitigation.
We aim to acknowledge a complete report within 7 days and provide a status update within 30 days. Please allow reasonable time for a fix before public disclosure.