Do not disclose suspected vulnerabilities in a public issue. Use the repository's Security tab and select Report a vulnerability to send the maintainers a private report. If private vulnerability reporting is not available, contact the repository owner through a private channel before sharing details publicly.
Include the affected version, reproduction steps, impact, and any suggested mitigation. Maintainers will acknowledge the report, investigate it, and coordinate disclosure and a fix as appropriate.
Until a stable release policy is published, only the latest release receives security fixes. Users should upgrade to the newest available version.