Security fixes are made to the latest release. A repository may list further supported versions in its own README.
Do not open a public issue. Report it privately through GitHub: Report a vulnerability.
Include:
- the affected version, exactly as released, or the full commit SHA;
- the steps to reproduce it;
- what an attacker could do with it.
Reports produced by an automated scanner or an AI tool must be reproduced and confirmed by you before you send them. Say which tool found it, as the AI Contribution Policy requires. Unconfirmed tool output will be closed.
We prioritise every confirmed security issue and will keep you informed while it is fixed.