Until the first stable release, security fixes are applied only to the latest commit on the default branch.
Do not open a public issue for a suspected vulnerability.
Use GitHub's private vulnerability reporting feature on the repository's Security tab. If private reporting is not enabled, contact a maintainer privately and ask for a secure reporting channel without including exploit details in the initial message.
Include the affected component, reproduction steps, impact, and any suggested remediation. Remove secrets and personal data from reports.
Maintainers should acknowledge a report within seven days and provide status updates as the issue is investigated. Public disclosure should be coordinated with the maintainers after a fix or mitigation is available.