Security fixes go into the latest release of spxtacular on PyPI.
Please report vulnerabilities privately through GitHub security advisories: open the repository's Security tab and choose Report a vulnerability (https://github.com/tacular-omics/spxtacular/security/advisories/new). Do not open a public issue.
Include the affected version, steps to reproduce, and the impact you expect. You should get a reply within seven days. Once a fix is released, the advisory is published and reporters are credited if they wish.