Security fixes target the latest code on main and the latest tagged release.
Do not open a public issue for an unpatched vulnerability or include secrets in an issue, pull request, log, or reproduction artifact. Use GitHub's private vulnerability reporting/security-advisory flow for this repository. Include:
- affected revision and environment;
- minimal reproduction steps;
- expected impact;
- any proposed mitigation.
If private reporting is unavailable, contact the repository owner privately through GitHub before public disclosure.