Only the latest stable release receives security fixes.
Report vulnerabilities privately through GitHub Security Advisories. Include affected versions, platform, reproduction steps, impact, and any known mitigation. Do not open a public issue for an undisclosed vulnerability.
An initial acknowledgement is targeted within seven days. Fix and disclosure timelines depend on severity, exploitability, and coordination needs.
For the current trust boundaries and known limitations, see
docs/SECURITY.md.