Do not open a public issue for a vulnerability involving crafted save files, resource exhaustion, parser crashes, or disclosure of private save data. Use GitHub's private vulnerability-reporting flow when it is enabled for this repository, or contact the maintainer privately through the repository profile.
Please include the reader version, operating system, a minimal reproduction that contains no real player or server data, and the expected and actual behaviour. Reports are acknowledged as soon as practical and are assessed before public disclosure.
Security fixes are made on the latest published release and the main branch.
Older releases may be fixed when the issue is straightforward to backport.