The current 0.1.x release line receives security fixes until a newer release
line supersedes it. Development snapshots and older superseded versions are not
separately supported.
Report vulnerabilities privately through GitHub Security Advisories. Do not open a public issue for an undisclosed vulnerability.
Include the affected version and module, provider and transport when relevant, Java and Spring Boot versions, impact, and a minimal sanitized reproduction. Never include API keys, authorization headers, real customer state, or other secrets. If logs are necessary, redact request and response bodies unless the specific field is essential to reproduce the issue.
The maintainer will coordinate investigation and disclosure through the private advisory. No response or fix deadline is guaranteed.