Security fixes are applied to the current published release and the default branch. Older releases may be superseded by a corrected immutable release instead of receiving a backport.
Do not open a public issue for a suspected vulnerability. Email hello@thalovant.com with:
- the affected repository, version, or commit;
- the impact and affected configuration;
- minimal reproduction or verification steps; and
- a suggested mitigation or fix, when available.
Do not include real customer data, credentials, tokens, identity files, or secret values in the report. Coordinate public disclosure with the maintainers after a fix is available.