Please do not open a public issue for security vulnerabilities.
Instead, use GitHub's private vulnerability reporting on the affected repository (Security → Report a vulnerability), or email amr.abdel@gmail.com.
You'll get an acknowledgement within a few days. Once a fix is ready it ships as a patch release through the standard release pipeline.
The latest released version of each package is supported. Security fixes are released as patch versions.