Until the first release, only the latest commit on the default branch receives security fixes.
Do not disclose a suspected vulnerability in a public issue. Use GitHub's Report a vulnerability link on the repository's Security tab. Include affected versions, impact, a minimal reproduction, and any suggested mitigation. Please avoid including real credentials or private user data.
The maintainer must enable Settings → Security → Private vulnerability reporting before making the repository public. If that feature has not yet been enabled, do not publish vulnerability details; open a nonsensitive issue asking the maintainer to enable a private reporting channel.
This project does not currently promise a response-time SLA or operate a bug-bounty program.