Only the latest maintained major version will receive security updates. Older versions may no longer be supported and may have known vulnerabilities.
If you find a security vulnerability, please do NOT open a public issue. Instead, use Report a vulnerability (found under Security and quality) on this repository to submit your report or patch confidentially. This allows the maintainers to investigate the issue privately and work with you on a fix.
If you're unsure whether something is a security vulnerability, ask yourself:
- Can I access something that's not mine, or something I shouldn't have access to?
- Can I disable something for other people?
If the answer to either question is "yes", you're probably dealing with a security issue. Note that even if you answer "no" to both questions, you may still be dealing with a security issue, so if you're unsure, report it privately, too.