Security fixes are applied to the latest published release. Older releases may not receive patches.
Please use GitHub's private vulnerability reporting form under the repository's Security tab. Include the affected version, impact, reproduction steps, and a minimal proof of concept. Do not open a public issue for an unpatched vulnerability and do not include Minecraft access tokens, alert tokens, shared secrets, or an unredacted configuration file.
For ordinary bugs without security impact, use the public bug-report template.