Do not open a public issue for security problems.
Report vulnerabilities privately, either through GitHub private vulnerability reporting or by email to info@gopherium.com.
You will receive an acknowledgement within 7 days. Please include a description of the issue, a proof of concept if you have one, and the version or commit you tested against. Coordinated disclosure is appreciated: give us a chance to ship a fix before publishing details.
Only the latest release receives security fixes. While the project is at v0.x there are no backport guarantees.
In scope: flaws in the code this module ships. Out of scope: how a consuming application wires it into its stack.