Please do not open a public issue for a suspected vulnerability. Use GitHub private vulnerability reporting and share what you know. Helpful details can include the affected version or surface, a non-sensitive example, observed impact, and a possible mitigation, but a complete analysis or proposed fix is not required.
Security work generally focuses on the current default branch and latest release. No older release, current release, response, triage, fix, disclosure date, or future maintenance is guaranteed.
The repository owner decides how a private report is assessed, disclosed, and released. Private intake does not authorize public disclosure or implementation. Security changes still use the applicable review, compatibility, and release checks in GOVERNANCE.md.