Only the latest published release receives security updates.
Use GitHub private vulnerability reporting to report suspected vulnerabilities. Do not open a public issue for a vulnerability.
Maintainers will acknowledge a report within three business days and coordinate next steps privately.