Security fixes are provided for the latest released minor version. Users should upgrade to the newest patch release before reporting a suspected known issue.
Do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting for this repository, or contact the maintainer at the address listed in pyproject.toml. Include the affected version, impact, reproduction steps, and any suggested mitigation. Do not include production keys, plaintext, ciphertext, credentials, or customer data.
You should receive an acknowledgment within seven days. Disclosure timing will be coordinated after the report is reproduced and a fix is available.
Reports about plaintext key exposure, authentication or authorization outside these model fields, compromised application processes, and properties explicitly documented under README security limitations may be out of scope unless the package behaves contrary to its documented guarantees.