Only the latest commit on the default branch is supported with security fixes.
Please do not open a public issue for security-sensitive reports.
Instead, report vulnerabilities through GitHub Security Advisories by using the repository's "Report a vulnerability" flow.
When possible, include:
- a clear description of the issue
- affected files or endpoints
- reproduction steps or a proof of concept
- impact assessment
- suggested remediation, if available
The maintainer will try to acknowledge valid reports within 7 days and provide updates as fixes are prepared.