The current 0.1.x release line is supported. Security fixes are released in
the newest supported version rather than backported to unpublished builds.
While the repository is private, report vulnerabilities through the existing private QualityMax security contact rather than an issue tracker. Do not include credentials, customer data, or production logs in a report.
Before any public release, a maintainer must enable and verify GitHub Private Vulnerability Reporting. Until that verification is recorded in the release ticket, do not open public issues for security reports and do not make the repository public.