Security fixes are applied to the latest release on the main branch.
Please do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting for this repository when available, or contact the maintainer privately through the GitHub profile. Include a clear reproduction, impact, and any suggested mitigation.
Do not include real API keys, access tokens, or private source code in a report. We will acknowledge a report within 7 days and work with you on disclosure after a fix is available.