Security fixes are generally provided for the latest maintained version of each project.
Please do not disclose security vulnerabilities publicly.
Instead:
- Contact the maintainer privately.
- Include a detailed description.
- Provide reproduction steps if possible.
- Explain the potential impact.
After a report is received:
- The issue will be reviewed.
- A fix will be developed if necessary.
- Responsible disclosure practices will be followed.
Thank you for helping keep projects secure.