Security fixes target the current master branch and latest release.
Report suspected vulnerabilities through this repository's private GitHub security-advisory flow. Do not open a public issue for path traversal, arbitrary file access, registry corruption, unsafe remote retrieval, or credential exposure.
Remove account names, paths, hostnames, addresses, and catalog content from diagnostics. Never attach a live registry database, private catalog, SSH material, or credentials.