Security fixes are made on the latest released driver version. Supported
Metabase, Mimir, and Prometheus versions are listed in README.md and the
compatibility workflow.
Do not open a public issue for a suspected vulnerability. Use GitHub's private security advisory reporting for this repository and include reproduction steps, the affected driver version, and relevant backend versions. Do not include live credentials, tokens, or tenant data.
Release JARs are accompanied by SHA-256 checksums, CycloneDX SBOMs, GitHub build provenance, and keyless Sigstore bundles.