Only the current source on the default branch is actively maintained. There is no published release yet.
Do not post passwords, OAuth tokens, personal email content, verification codes, or exploit details in a public issue.
Use GitHub's private vulnerability-reporting channel for this repository if it is enabled. If it is not available, open a minimal public issue that asks the maintainers for a secure reporting channel and includes no sensitive detail. Include the affected version or commit, a concise impact description, reproduction conditions, and any mitigation you found.
Maintainers should acknowledge reports, assess impact, coordinate a fix, add a regression test when practical, and disclose only after affected users have a reasonable update path.