Security fixes are applied to the latest revision of the main branch. Older revisions are not supported.
Do not open a public issue for vulnerabilities, leaked credentials, or other sensitive reports.
Use GitHub's private vulnerability reporting. If private reporting is unavailable, open a public issue asking the maintainer for a private contact method without including sensitive details.
Include the affected platform, reproduction steps, impact, and any suggested remediation. You should receive an initial response within seven days.
Before publishing a fork, review its complete Git history as well as the current files. Removing a secret from the latest commit does not remove it from earlier commits. Rotate any credential that may have been committed, even if the commit was never merged.