Security updates are provided for the latest published preview or stable release.
Please use GitHub's private vulnerability reporting for this repository. Do not open a public issue with exploit details. Include the affected version, impact, reproduction steps, and any suggested mitigation. You can expect an initial acknowledgement within seven days.
Release binaries include SHA-256 checksums and GitHub build provenance. Treat checksums as transport-integrity protection; use the GitHub provenance record when verifying artifact origin.