Security fixes are applied to the current main branch and included in the next
release. Older releases may not receive backports.
Do not open a public issue for a suspected vulnerability. Use GitHub's private Report a vulnerability form instead.
Include the affected version or commit, impact, reproduction steps, and any suggested mitigation. Reports are acknowledged through the private advisory; status and disclosure timing are coordinated there so users can update before technical details are published.
For non-security bugs and usage questions, use the public issue tracker or Discussions.