The current 0.x release line is supported. Security fixes are delivered in the latest published package versions.
Please report vulnerabilities privately through the repository's Security tab using a GitHub Security Advisory. Do not open a public issue and do not include proof-of-concept exploit details in public discussions.
Maintainers will acknowledge a valid report within 7 calendar days. We will assess the report, coordinate disclosure when a fix is available, and credit reporters when they wish to be credited.