Security updates are handled on the default branch. Please use the latest commit on main unless a release line is explicitly documented.
Please do not open a public issue for a security vulnerability.
Use GitHub's private vulnerability reporting feature if it is enabled for this repository. If it is not enabled, contact a maintainer through a private channel and include:
- A clear description of the vulnerability.
- Steps to reproduce the issue.
- The affected commit, version, or configuration.
- Any known workarounds or mitigations.
We will try to acknowledge valid reports promptly and coordinate a fix before public disclosure.