Security fixes target the latest release line. Older lines may receive a fix when the change can be applied without changing their supported runtime or persisted contract.
Please do not open a public issue for an undisclosed vulnerability. Use GitHub's private security advisory workflow for this repository, or contact the maintainers through the security contact listed in the repository profile. Include the affected package and version, a minimal reproduction, impact, and any proposed mitigation.
Allow time for triage before public disclosure. Do not include secrets, production payloads, or personal data in the report.