Do not open public issues for vulnerabilities. Send a private GitHub Security Advisory to the repository maintainers with affected versions, reproduction steps, impact, and any suggested mitigation. Do not include real secrets or third-party data.
The latest release is supported. Maintainers will acknowledge credible reports, investigate, coordinate a fix and disclosure, and credit reporters who request it.
Deployers must replace example credentials, keep production private-network access disabled unless intentionally required, use network egress controls, protect the database volume, and terminate TLS at a trusted reverse proxy.