Security fixes are provided for the latest released version. Older releases may not receive security updates.
Do not open a public issue for a suspected vulnerability.
Use GitHub's private vulnerability reporting for this repository. Include, where possible:
- affected version and component
- steps to reproduce
- expected impact
- any known workaround
Issues involving expected behavior described by the ownership, representation, or trust contracts should use the normal issue tracker instead.
Please allow time to investigate before disclosing the issue publicly.