Only the latest published tag receives security fixes. Older tags are not patched; upgrade to the latest release if you find a vulnerability.
Report a vulnerability privately through GitHub Security Advisories on this repository (the "Security" tab, "Report a vulnerability"). Do not open a public issue or pull request for a security problem.
Include what you found, the affected version, and steps to reproduce it if you have them. You will get an acknowledgement, and a fix or a mitigation plan once the report is confirmed.