Security fixes are provided for the latest release on main. Older releases are not supported unless a maintainer explicitly designates a maintenance branch.
Do not open a public issue for a suspected vulnerability. Submit a private report through GitHub Security Advisories.
Include the affected version or commit, impact, reproduction steps, and any proposed mitigation. Do not include live credentials or unrelated personal data. Maintainers will acknowledge the report through the private advisory and coordinate disclosure after a fix is available.
If a credential appears in the repository, revoke or rotate it immediately. Removing a file from the current branch does not remove the credential from Git history.
Thank you to all contributors who help enhance the security of this project.