Security reports are accepted for the current main branch and the latest
tagged prerelease or release. Once multiple releases exist, fixes will normally
target the latest v0.x line. Report vulnerabilities privately through GitHub's
private vulnerability reporting feature; do not open a public issue containing
exploit details or secret material. If private reporting is unavailable, open a
public issue asking the maintainer for a private contact channel without
including vulnerability details.
Include affected version/platform, reproduction steps, impact, and suggested mitigation. Maintainers will acknowledge a complete report within seven days and coordinate disclosure. This project is unaudited research software.