Security fixes are handled for the latest release on the default branch.
Do not open a public issue for a vulnerability.
Report security concerns by emailing the maintainer or using GitHub private vulnerability reporting if it is enabled for the repository.
Please include:
- Affected files or dependencies.
- Reproduction steps.
- Impact and exploitability notes.
- Suggested fix, if known.
You should receive an initial response within 7 days.