Security fixes are applied to the latest released version and to main.
Older released versions do not receive backported fixes; upgrade to the
latest release to pick up a security fix.
Do not open a public issue for a suspected vulnerability or exposed credential. Use GitHub's private vulnerability-reporting feature for this repository. If it is unavailable, contact the repository owner privately through their GitHub profile and include a clear reproduction or impact description.
Do not include tokens, passwords, private keys, or production data in the report. Treat any credential committed to the repository as compromised and revoke it with its provider immediately.