Before the first stable release, security fixes are provided for the latest published version only.
Do not open a public issue for a suspected vulnerability. After the GitHub repository is created, use its private security advisory feature to contact the maintainers. Include reproduction steps, affected versions, expected impact, and any proposed mitigation.
Please allow maintainers time to confirm the report and prepare a coordinated fix before public disclosure.