Report vulnerabilities privately through GitHub's security advisory interface for Crosseno/core. Do not include sensitive exploit details in public issues.
Supported releases receive fixes according to their latest compatible minor release. Treat snapshots as untrusted input: configure limits appropriate to the host and do not disable schema or domain validation.