Do not report vulnerabilities in a public issue. Once the public repository exists, use GitHub private vulnerability reporting to contact the repository owner. Include the affected version, a minimal reproduction, impact, and a proposed mitigation when available.
Supported releases are the latest published release and the current main branch.