Security fixes target the latest released version and the main branch.
Use GitHub private vulnerability reporting. Do not disclose a suspected vulnerability in a public issue.
Include affected versions, reproduction steps, impact, and any known mitigations. Maintainers will acknowledge the report, coordinate validation and remediation, and publish an advisory when disclosure is safe.
Never include registry credentials or repository tokens in a report unless a maintainer provides a secure transfer channel.