Security fixes are applied to the latest released version.
Do not open a public issue for a vulnerability.
Use GitHub's Report a vulnerability option in the repository's Security tab. Include:
- the affected version;
- the operating system and agent;
- steps to reproduce;
- the impact you observed;
- any suggested fix.
You should receive an initial response within seven days.