Only the latest release is actively supported with security fixes.
Please do not open a public GitHub issue for security vulnerabilities.
Email nick.marden@tightlinesoftware.com with:
- A description of the vulnerability and its potential impact
- Steps to reproduce or a proof-of-concept (if available)
- Any suggested mitigations you have in mind
You should receive an acknowledgment within 48 hours. We'll work with you on a disclosure timeline once the severity and fix are understood.