Please do not report security vulnerabilities in a public GitHub issue.
Send a private report to the DR-IT security contact designated for the repository. Include the affected version, a clear description of the issue, reproduction steps or a proof of concept, and any relevant logs or sample files. Do not include secrets in the report.
We will acknowledge reports as soon as practical, investigate the impact, and coordinate disclosure and remediation with the reporter.
Security fixes are considered for the latest released version and the current development branch. Older versions may require upgrading before a fix is provided.