Only the latest release on PyPI receives security fixes.
Do not open a public issue.
Report vulnerabilities via GitHub private security advisory.
Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
You will receive a response within 72 hours. If confirmed, a patch will be released promptly and you will be credited unless you prefer otherwise.