Use GitHub's private vulnerability reporting: open this repository's Security tab and select Report a vulnerability. Do not open a public issue for a security vulnerability.
Reports are reviewed on a best-effort basis. This open-source project is maintained by an individual. No deadline or financial reward is promised.
The current main branch is supported. Security fixes are not backported to older tags.
Code in this repository is in scope. Report vulnerabilities in third-party dependencies to the relevant upstream project.