Security fixes are applied to the latest version on the default branch. Older releases are not currently supported.
Please do not report suspected vulnerabilities in public issues. Instead, email the maintainer at wehttam@gmail.com with a description, affected versions, steps to reproduce, and any suggested fix or mitigation.
You should receive an acknowledgement within seven days. We will assess the report, coordinate a fix and disclosure timeline with you, and credit you in the release notes when appropriate.