Security fixes are applied to the latest release and main.
Do not disclose suspected vulnerabilities in a public issue. Use Report a vulnerability in the repository's Security tab. Include the affected version, reproduction steps, expected impact, and a suggested mitigation when available. Reports should receive an acknowledgement within seven days.
Unsafe catalogue parsing, dependency compromise, arbitrary file writes, credential exposure, and unintended publication of restricted data are in scope. Statistical disagreement, catalogue revisions, and third-party service availability are not software security vulnerabilities.