Security fixes are provided for the latest published release.
Use GitHub private vulnerability reporting instead of a public issue. Include the affected version, a minimal reproduction, expected impact, and suggested mitigation. Do not include credentials or production data.
Middleware executes with the same authority as the application. Treat third-party middleware as application code and review it before installation.