Do not report vulnerabilities in public issues. Use GitHub's private vulnerability reporting for this repository. Include the affected revision, reproduction steps, impact, and a minimal patch or mitigation when available.
Supported code is the latest main revision and the latest tagged release. Security fixes are published with the next release when disclosure permits.