Nalanda is pre-1.0 and ships from the latest release. Security fixes land in a new release on the current line; older tags are not patched.
Please report security issues privately rather than opening a public issue. Use GitHub's private vulnerability reporting to open a confidential advisory, and you'll get a response as soon as possible.
Nalanda handles API keys and tokens for Jellyfin, Radarr, Sonarr, TMDB, and MDBList. When sharing reproduction steps, please redact any secrets.