Only the latest released version is considered supported for security fixes.
Please do not report security vulnerabilities in public issues.
Until repository security channels are fully configured, report vulnerabilities through a private maintainer contact channel in your organization.
Include:
- A clear description of the issue
- Steps to reproduce
- Impact assessment
- Suggested fix (if available)
- We will acknowledge receipt as soon as possible.
- We will investigate and prepare a fix.
- Public disclosure should happen only after a fix is available.