Security fixes are provided on a best-effort basis for the latest version on the default branch.
If you discover a security issue, please do not open a public issue with exploit details. Instead:
- Prepare a concise report with impact, affected endpoints, reproduction steps, and any proof of concept.
- Share the report privately with the project maintainers through the repository security advisory flow or your private maintainer channel.
- Allow time for triage, validation, remediation, and coordinated disclosure before publishing details.
We will acknowledge receipt as soon as possible, validate the report, and work toward a fix and disclosure timeline.