Security fixes target the latest published release and the default branch. Older releases may be assessed when the impact warrants it, but they are not guaranteed to receive a backport.
Please do not open a public issue for a suspected vulnerability. Use the repository's Security tab and select Report a vulnerability to send a private report.
Include the affected project and version, impact, reproduction steps or a proof of concept, and any suggested remediation. You should receive an initial acknowledgement within seven days. Findings will be coordinated privately until a fix or mitigation is available.
Good-faith research and responsible disclosure are welcome. Please avoid privacy violations, service disruption, destructive testing, and accessing data that is not your own.