Security fixes target the current 1.x release line and the default branch. Older releases may remain useful for format compatibility but are not maintained as security branches.
Use GitHub private vulnerability reporting for unicbm/demotracer. Do not publish exploit details, signing material, private server data, or a working proof of concept in a public issue.
Include the affected version or commit, component, reproduction conditions, impact, and the smallest safe evidence needed to verify the report. If private reporting is unavailable, open a public issue requesting a private contact channel without disclosing vulnerability details.