During the alpha phase, only the latest published prerelease is eligible for best-effort security fixes. Older prereleases are unsupported. If no version has been published yet, there is no supported release.
Do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting to include reproduction steps, affected revisions and the expected impact.
Reports will be acknowledged when reviewed. A remediation timeline depends on severity and maintainer availability; no response-time guarantee is made during the alpha phase. Confirmed fixes will be disclosed after a patched release or after affected users have had a reasonable opportunity to update.