Only the latest tagged release receives security updates. Earlier releases and unreleased development snapshots are not supported security branches. Reports remain welcome for any version, but fixes target the latest release.
Please use GitHub's private vulnerability reporting for issues that could expose portal credentials, authorize the wrong connection, duplicate an uncertain POST, escape the systemd sandbox, or turn installation into a network action.
Do not include a real portal token, connection UUID, cookie, captured portal page, packet capture, or host journal in a public issue. If private reporting is temporarily unavailable, open a public issue containing no sensitive details and ask the maintainer to establish a private channel.
Security advisories will identify the affected and fixed release versions.