Security fixes are provided for the latest published release. Please upgrade to the latest release before reporting an issue that may already be fixed.
Please report suspected vulnerabilities privately using GitHub's private vulnerability reporting.
Do not disclose security vulnerabilities in public issues, discussions, or pull requests.
Include, where possible:
- The affected version or commit.
- A description of the vulnerability and its potential impact.
- Steps to reproduce it, with a minimal proof of concept.
- Any suggested mitigation or fix.
Do not include real credentials, personal information, or confidential client data in your report.
We will use the private report to discuss the findings and coordinate any fixes and public disclosure.
For non-security bugs and feature requests, use GitHub Issues.