The latest release on master receives security fixes.
This library parses untrusted file formats, so security reports are taken seriously — especially memory exhaustion (ZIP bombs, decompression bombs), parser crashes on malformed input, and path traversal in archive handling.
Please report vulnerabilities privately via GitHub Security Advisories rather than opening a public issue. Include the affected format/parser, a description of the issue, and a proof-of-concept file if possible.
You can expect an initial response within a week.