Please report security vulnerabilities by opening a private security advisory on this repository, or by emailing jon@carpediemsystems.co.uk. Do not open a public issue for a suspected vulnerability.
Please include what you have: a description of the issue and its likely impact, steps to reproduce or a proof-of-concept, and any mitigation you are aware of.
You will receive an acknowledgement within 7 days. This is a solo-maintained project, so that is a commitment to reply — not to have a fix ready by then. Work on a confirmed vulnerability starts as soon as I am able, and I will keep you posted on progress.
If a fix is warranted you will be credited in the release notes, unless you would rather not be.
Only the latest published release is supported.