Security policy

Reporting a vulnerability

Please do not open a public issue for a security problem. Use private vulnerability reporting instead: only the maintainer sees it.

Include what you found, the version or commit, and the steps to reproduce it. Expect a first answer within a week. Only the latest release is supported.