Security fixes are applied to the latest code on main. Older commits and deployment forks are not
maintained as separate release lines.
Please do not open a public issue for a suspected vulnerability.
Use GitHub's Report a vulnerability action on the repository's Security tab to send a private report. Include the affected area, reproduction steps, impact, and any suggested mitigation.
You should receive an acknowledgement within seven days. Please allow time for a fix to be prepared before disclosing the issue publicly.
Do not include real credentials, private transcripts, or other user data in a report. Use minimal test data when demonstrating the issue.