Security fixes target the latest published version of each package. Maintainers may backport a fix when the impact and adoption justify it, but older releases are not supported by default.
Do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting for this repository. If that channel is unavailable, email wangrenren611@gmail.com with:
- the affected package and version;
- reproduction steps or a proof of concept;
- expected impact and any known workarounds;
- whether disclosure is time-sensitive.
You should receive an acknowledgement within seven days. We will coordinate validation, remediation, release, and disclosure with the reporter. Please avoid accessing data that is not yours, disrupting services, or publishing details before a fix is available.
For ordinary bugs and hardening ideas that do not expose a security boundary, use the public issue tracker.