The current 0.1.x line is supported. Security fixes target the latest published patch release until a newer minor line replaces it.
Repository owners must keep GitHub private vulnerability reporting enabled. Use the private advisory form for redaction bypasses, credential exposure, unsafe automatic-retry decisions, unbounded parsing or traversal, denial-of-service cases, and release-workflow or artifact issues.
Do not include real credentials, prompts, model output, customer data, or exploitable details in a public issue. If private reporting is unavailable, open a minimal public issue asking the maintainers to enable a private channel, without sensitive details or a proof of concept.
Reports are most useful when they include affected versions, a minimal synthetic fixture, observed behavior, expected behavior, and the runtime used to reproduce the issue.