Security fixes are applied to the latest published release and the default branch.
Please do not open a public issue for a security vulnerability. Contact the maintainers privately with a clear description, reproduction steps, affected version, and potential impact.
Until a private reporting address is published, use the repository owner's private security-advisory workflow on the hosting service.
Please allow reasonable time for investigation before public disclosure.