Report security issues through a private GitHub Security Advisory. Do not disclose exploitable details, subscription URLs, tokens, router credentials, private configurations, or unredacted logs in public Issues.
Include the affected package and version, reproduction conditions, expected impact, and a minimal redacted test case. Use GitHub Issues for ordinary configuration and usage questions after removing sensitive data.
Security fixes are applied to the current main branch. Older releases are not
guaranteed to receive backports.