Security fixes are provided for the latest stable release. Pre-release builds are supported only while they remain the current published candidate.
Use the repository's private vulnerability reporting channel. If that channel is unavailable, contact a maintainer through a private channel listed by the repository owner.
Do not open a public issue containing credentials, OAuth material, QR codes, private provider endpoints, tenant identifiers, real chat or document IDs, message or document content, local paths, logs, databases, screenshots, or diagnostic bundles.
Include only a minimal synthetic reproduction. Maintainers may ask for a locally generated redacted diagnostic report. The project never requires a reporter to upload real business data to a public or maintainer-operated service.
Maintainers will acknowledge a private report, assess affected versions, prepare a fix and regression test, and coordinate disclosure after a patched release is available. Credentials or tenant data included accidentally must be revoked or removed by their owner; the project will not copy them into issue trackers or release evidence.