Security fixes are considered for the latest published release on PyPI and for the current development tip when preparing the next patch release.
Please do not open a public GitHub issue for security vulnerabilities.
Prefer reporting through GitHub Security Advisories for this repository. If that is unavailable, email travis.j.kessler@gmail.com with a description of the issue, impact, and reproduction steps if possible.
We will acknowledge receipt when we can and work on a fix and coordinated disclosure appropriate to the severity of the report.