Security fixes are applied to the latest revision of the default branch. This project is currently pre-1.0 and does not maintain older release branches.
Do not open a public issue for a vulnerability that could overwrite files, escape a project or package directory, expose private QA material, or replace an installed package unsafely. Use the repository host's private vulnerability reporting feature instead. Include the affected command, a minimal reproduction, and the expected versus observed filesystem scope.
Never include real credentials, private pet projects, or personal reference images in a report. Synthetic fixtures are preferred.