Security fixes are developed on dev and included in the next immutable release. Only the latest published production release is supported after a replacement release is promoted successfully.
Use GitHub private vulnerability reporting. Do not open a public issue for an undisclosed vulnerability and do not include credentials, tokens, session cookies, private keys, personal data, or production logs containing secrets in a report.
Include the affected component and version, reproduction steps, impact, and any suggested mitigation that can be shared safely. Maintainers will acknowledge the report, investigate it privately, coordinate a fix and disclosure, and credit the reporter when requested and appropriate.
If a real credential may have been exposed, revoke or rotate it immediately; removing it from Git history is not sufficient.