Security fixes are considered for the current version on the main branch. Historical versions and forks may not receive security updates.
Please do not open a public issue for a suspected security vulnerability.
Use GitHub's private vulnerability-reporting feature from this repository's Security tab, when available. Include a concise description of the issue, affected files or components, steps to reproduce, impact, and any proposed mitigation. If private reporting is unavailable, contact the repository owner through GitHub and avoid disclosing exploit details publicly.
The maintainer will review reports in good faith, aim to acknowledge receipt within seven days, and coordinate a remedy or disclosure plan when the report is verified. No response-time guarantee is implied.
This policy applies to code and published assets maintained in this repository. Please provide enough technical detail to reproduce the issue without accessing systems or data you do not own or have permission to test.