Unless a release states otherwise, security fixes target the latest published custom release. Older releases may no longer receive fixes.
Use the repository's private GitHub vulnerability-reporting feature when it is available. Do not open a public issue containing credentials, production data, private endpoints, or exploit details.
If private reporting is unavailable, open a minimal issue requesting a private contact channel without including sensitive technical details.
Include the affected version, deployment type, impact, reproduction conditions, and any relevant logs with secrets removed. Maintainers will assess scope and coordinate disclosure based on severity and available fixes.
Provider terms-of-service questions, exposed deployment credentials, and operator misconfiguration are not automatically product vulnerabilities. Reports are still welcome when the project can improve defaults, validation, or documentation.