This is a personal open-source project. Only the latest release on main
receives security fixes.
Please do not open a public issue for security problems.
Report privately via GitHub's private vulnerability reporting, which notifies the maintainer directly and keeps the report confidential until a fix ships.
Expect an initial response within roughly a week. As a single-maintainer project there is no formal SLA, but reports are taken seriously and credited in the advisory unless you'd rather stay anonymous.
In scope: this repository's source, its GitHub Actions workflows, and the artifacts it publishes.
Out of scope: vulnerabilities in third-party dependencies (report those upstream; Dependabot tracks them here), and issues that require an already compromised local machine.