Security fixes target the current main branch and the latest formal Release. Older Releases are retained for historical reference and may no longer receive fixes.
Use GitHub Private Vulnerability Reporting for vulnerabilities, suspected credentials, privacy exposure, or unsafe network recovery behavior. Do not open a public Issue containing exploit details or sensitive data.
Reports should include the affected version, platform, reproduction steps using synthetic data, expected impact, and any safe diagnostic output. Never attach real PCAP/PCAPNG files, configuration, logs, recovery journals, tokens, device identifiers, interface details, or infrastructure addresses.
The maintainer will acknowledge a complete report, assess affected versions, and coordinate remediation and disclosure. No response-time or bounty commitment is implied.