Security fixes are provided for the latest tagged release. Operators should upgrade promptly; older releases may receive a fix only when a supported migration path requires it.
Do not open a public issue. Use GitHub's Report a vulnerability flow in the repository Security tab. Include affected versions, reproduction steps, impact, and any suggested mitigation.
We aim to acknowledge a report within 3 business days, provide an initial assessment within 7 business days, and coordinate disclosure after a fix is available. Please allow reasonable remediation time before publishing details.
Release artifacts include SHA-256 checksums, SPDX SBOMs, Sigstore bundles, and GitHub build-provenance attestations. Verify these before production rollout.