2.0.7
- fix(security): re-stuff constructor headers to prevent SMTP smuggling
- packaging / meta updates (#26)
header_list holds dot-unstuffed logical values; when serialising them to an SMTP DATA sink they must be re-dot-stuffed, or a header line reading as "." lands as a bare end-of-DATA terminator on the backend (transaction injection). ending_dot now forces wire stuffing to be preserved.
Ref: GHSA-rp4q-8m6x-c43c