Only the latest released version receives security fixes during pre-release development.
Use GitHub private vulnerability reporting for this repository. Do not disclose vulnerabilities in public issues. Include affected versions, impact, and a minimal synthetic reproduction without real personal data or production credentials.
Maintainers will acknowledge a report, assess severity, coordinate a fix and disclosure, and keep the reporter informed. Response times are best effort until a formal service level is published.
Security scope includes token collisions, raw-data leakage, detector bypasses, unsafe key handling, and regular-expression denial of service. Detection errors can have privacy consequences.