Only the latest major version receives security fixes.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Report them privately through GitHub Security Advisories, or by email to the maintainer listed in composer.json.
Please include:
- The affected package version
- A description of the vulnerability and its impact
- Steps or code to reproduce it
You will receive a response as soon as possible. Once a fix is released, the vulnerability will be disclosed publicly with credit to the reporter, unless you prefer to stay anonymous.