Security fixes are applied to the latest released version and the main
branch. Older releases may not receive patches.
Please do not open a public issue for a suspected vulnerability.
Use GitHub's Security tab and select Report a vulnerability to send the maintainers a private report. Include affected versions, impact, reproduction steps, and any suggested mitigation. Please avoid accessing data or systems that are not yours while investigating.
If private vulnerability reporting is unavailable, contact an ArchAstro maintainer privately and ask for a secure reporting channel without including sensitive details in the initial message.