Security fixes are made on the latest release line and main. Older releases
receive fixes on a best-effort basis.
Please report suspected vulnerabilities privately through GitHub Security Advisories. Do not open a public issue until the report has been assessed.
Include the affected version or commit, the impacted interface, reproduction steps, and the expected security impact. Remove credentials, private datasets, model weights, and other sensitive material from the report. You should receive an acknowledgement through GitHub; remediation timing depends on severity and the availability of a safe fix.