Security fixes target the current stable 1.x line. Upgrade to its latest
patch release before reporting a vulnerability. Earlier prereleases are unsupported.
Please do not disclose an unpatched vulnerability in a public issue. Use the repository's GitHub private vulnerability-reporting form as the primary reporting route. Include a minimal reproduction, affected versions, impact, and any mitigation you know.
If private reporting is unavailable, open a public issue containing no vulnerability details and only request a private maintainer channel. Do not disclose security details in a public issue. Wait for a private response before sharing any vulnerability detail.
The repository does not publish a security-response SLA. Acknowledgement and remediation timing therefore cannot be promised here. Reporters will be credited only with their permission.