Security fixes are prepared for the latest release and the main branch.
Users should upgrade to the latest release to receive fixes. Older releases
may not receive security updates.
Please report suspected vulnerabilities through GitHub's private vulnerability reporting feature on the VSL Security page. Do not report security issues in public issues, discussions, or pull requests.
Include the affected version or commit, the steps needed to reproduce the problem, its potential impact, and any known mitigations. Avoid including secrets or personal data in the report.
The maintainers will use the private advisory to acknowledge the report, investigate it, and coordinate a fix and disclosure with the reporter. No response-time guarantee is currently published; if the private reporting feature is unavailable, contact a repository maintainer privately through GitHub before sharing details publicly.