Security fixes are applied to the latest version on the main branch and the latest published release.
Please do not disclose suspected vulnerabilities in a public issue.
Report security issues privately through GitHub's repository security reporting mechanism when available. Include a clear description, affected component or workflow, reproduction steps, impact assessment, and any relevant logs or proof of concept.
Do not include secrets, access tokens, credentials, or other sensitive data in the report.
We will assess valid reports and document remediation through the appropriate security channel.