Security fixes are applied to the latest code on main.
Please do not post a suspected vulnerability in a public issue. Report it privately through the repository owner’s GitHub profile with:
- a clear description of the issue;
- affected files and versions;
- safe reproduction steps or a proof of concept;
- potential impact and any suggested mitigation.
You should receive an acknowledgement within seven days. Please allow time for a fix before public disclosure.