Please do not report security vulnerabilities in public issues.
Use GitHub private vulnerability reporting and include a minimal reproduction, affected versions, impact, and any known mitigations. Remove API keys, private benchmark results, and restricted dataset contents from the report.
Maintainers will confirm receipt and coordinate disclosure after a fix is available. Security fixes are supported on the latest commit of the default branch until versioned releases establish a different policy.