Until a formal release support policy is published, security fixes target the latest version on the default branch.
Do not open a public issue for a suspected vulnerability.
Use GitHub's private vulnerability reporting or open a private security advisory in the repository. Include:
- the affected version or commit;
- reproduction steps or a minimal proof of concept;
- the expected impact;
- any known mitigations.
Please allow maintainers time to investigate and coordinate a fix before public disclosure.