Before the first release, security fixes target main.
Do not open a public issue for a suspected vulnerability. Use GitHub private vulnerability reporting in the Security tab. Include the affected version or commit, impact, minimal reproduction, and any suggested mitigation.
The maintainer will acknowledge a report as soon as practical, validate its scope, and coordinate a fix and disclosure.
The threat model documents application responsibilities and non-goals. If a finding's scope is unclear, report it privately.