Security fixes are made against the latest development branch and the latest tagged release, if one exists.
Do not report security issues through public GitHub issues.
Use GitHub's private vulnerability reporting for this repository when it is available. If private reporting is not enabled yet, open a minimal public issue requesting a private reporting channel without disclosing exploit details.
Include the following when possible:
- affected version, commit, or installation method
- impact and expected severity
- reproduction steps or a proof of concept
- suggested mitigation, if known
Please give maintainers time to understand and address the issue before public disclosure.