Until a stable release exists, security fixes target the latest release and the default branch only.
Use the repository's Security → Report a vulnerability flow. Do not include exploit details, private code, credentials, or affected-user data in a public issue.
Include the affected version, operating context, impact, minimal reproduction, and any suggested mitigation. You should receive an acknowledgement through the private report thread. Disclosure timing will be coordinated there after impact and a fix are understood.
Reports are especially useful for unintended network access, reviewed-code execution, path traversal, unsafe output replacement, secret disclosure, denial of service within the documented input limit, packet prompt-injection weaknesses, and dependency or CI provenance issues.
The tool is not a sandbox, secret scanner, semantic verifier, or malware analyzer. Do not use it to process content you are not authorized to access. See the threat model and privacy policy.