Only the latest release (and main) receives security fixes.
Report vulnerabilities privately via GitHub's private vulnerability reporting — do not open a public issue for security problems.
Dependency advisories are monitored automatically: cargo audit runs in CI on
every dependency change and weekly (.github/workflows/security-audit.yml).