Security fixes are applied to the latest release and the main branch. Older tags may not receive backports.
Use the repository's Security → Report a vulnerability flow to open a private security advisory. Do not disclose an unpatched vulnerability in a public issue, discussion, or pull request.
Include the affected version or commit, reproduction steps, impact, relevant logs with personal data removed, and any proposed mitigation. Please avoid testing against systems, accounts, devices, or providers you do not own or lack permission to assess.
The maintainer will acknowledge a complete report when reviewed, coordinate validation and remediation, and credit the reporter unless anonymity is requested. No bug bounty is currently offered.
Provider outages, inaccurate forecasts, expected regional coverage gaps, and ordinary crashes without a security impact belong in the regular issue tracker.