Security fixes are applied to the latest release and the default branch. Older releases may not receive updates.
Use GitHub private vulnerability reporting when available. If private reporting is unavailable, contact the maintainers through the Lynavo GitHub organization before disclosing details publicly.
Include the affected version, macOS version, impact, reproduction steps, and any suggested mitigation. Use synthetic data and never include real clipboard contents, credentials, or personal information.
Please allow maintainers a reasonable opportunity to investigate and publish a fix before public disclosure. General bugs that do not have security impact can be reported through the public issue tracker.