Until the first stable release, security fixes are applied to the default branch only.
During anonymous review there is no public security contact that can safely be listed without revealing author identity. Please do not open a public issue for a suspected vulnerability. Use the repository host's private vulnerability reporting feature if it is enabled.
Before the repository is de-anonymized, maintainers must replace this section with a monitored security contact or enable private vulnerability reporting. Do not publish credentials, private dataset URLs, exploit details, or affected user data in an issue.