Only the latest release is supported with security fixes.
Please do not open a public GitHub issue for security vulnerabilities.
Email holden@arch.fyi with:
- A description of the vulnerability and its potential impact
- Steps to reproduce or a proof of concept
- Any suggested fix, if you have one
You will receive an acknowledgement within 48 hours. If the vulnerability is confirmed, a fix will be released as soon as possible and you will be credited in the changelog unless you prefer otherwise.