Security fixes are made on the current main branch while BAR is in active
development. Historical revisions are not supported.
Please do not open a public issue, discussion, or pull request for a suspected security vulnerability. Use the repository's Report a vulnerability flow on GitHub when it is available. Include a clear description, affected commit or configuration, reproducible steps, impact, and any proof of concept needed to understand the issue.
If private vulnerability reporting is not available, contact the repository owner privately through the GitHub profile and mark the message as a security report. Do not include secrets, credentials, or production data.
Reports are triaged privately. BAR will acknowledge a report when practical, work to reproduce and assess it, and coordinate disclosure after a fix or mitigation is available. This is a personal open-source project; response and fix timelines are best-effort rather than guaranteed.