This project supports security, bug fixes and feature development on the two most recent non-prerelease versions.
To report a vulnerability you can use github's private security report option before opening public issues on the repo.
While I sincerely appreciate and welcome reports of suspected security problems, please note that I am not currently running any bug-bounty programs.
Critical vulnerabilities will be disclosed via GitHub's security advisory system.