Do not report suspected vulnerabilities in public issues. Once the public repository is available, use its GitHub private vulnerability-reporting feature to provide reproduction details, affected versions, and potential impact.
Until that feature is configured, contact the project maintainer through the approved private support channel. Do not include credentials, tokens, or customer data in the report.
Security fixes are applied to the latest released version. The project may also publish fixes for an earlier release when maintainers determine that it is necessary and practical.