Security support covers the latest published release only.
Do not report vulnerabilities publicly. Use GitHub Private Vulnerability Reporting instead.
Include only a minimal sanitized reproduction. Do not include real credentials, tokens, personal data, or unrelated private information.
Reports are reviewed on a best-effort basis; there is no response-time SLA.
Bug reports and feature requests are welcome. External code contributions are not currently accepted.