Do not report suspected vulnerabilities in a public issue, pull request, Discussion, social post, or other public channel.
Use GitHub's private vulnerability reporting to share the affected version or commit, impact, reproduction steps, and any suggested mitigation. Do not include real user secrets or data when a minimal synthetic reproduction is possible.
The maintainer will acknowledge and assess reports through the private advisory. Please keep details private until a fix and disclosure plan have been agreed.
Security fixes target the current release and the built-from-scratch branch. Older releases may
require an upgrade rather than a backport.