Do not report suspected vulnerabilities with real private keys, passphrases, encrypted confidential files, operational fingerprints, or GnuPG home archives.
Open a private GitHub security advisory and include the affected version, sanitized reproduction steps, expected behavior, observed behavior, and a disposable test fixture.
The project supports the latest tagged release. Experimental branches and locally modified builds are evaluated on a best-effort basis.