Security fixes are made against the latest version on the default branch.
Please do not disclose a suspected vulnerability in a public issue, discussion, pull request, or Discord channel.
Use Security > Report a vulnerability on the GitHub repository. Include a clear description, affected version or commit, reproduction steps, impact, and any suggested mitigation. Do not include credentials or unrelated personal data.
The maintainer will acknowledge the report when practical, investigate it, and coordinate disclosure after a fix is available.