Security fixes are applied to the current production release and main.
Older release lines receive fixes only when maintainers explicitly identify
them as supported.
Do not disclose vulnerabilities in public issues, pull requests, discussions, or chat.
Use GitHub's Report a vulnerability form in the affected repository:
If you cannot use GitHub private vulnerability reporting, email tacticusplanner@gmail.com. Include the affected component, reproduction steps, impact, and any suggested mitigation. Do not include real user secrets or data unless a maintainer explicitly requests a secure transfer method.
Maintainers will acknowledge a report, investigate it, and coordinate disclosure and remediation with the reporter. Response and resolution times depend on severity and maintainer availability.