Security fixes are applied to the latest release and the main branch.
Use GitHub's private vulnerability reporting for this repository. Do not open a public issue for a suspected vulnerability. Include affected versions, reproduction steps, impact, and any suggested remediation. You can expect an initial acknowledgement within seven days.
Remove credentials, API keys, session cookies, and personal data from logs or configuration samples before submitting a report.