Security fixes are applied to the latest published release of the runtime image. Older image tags are not maintained.
Report vulnerabilities through a private GitHub security advisory. Do not include credentials, exploit details, or sensitive logs in a public issue, pull request, discussion, or workflow artifact.
Include the affected image digest or release, a minimal reproduction, impact, and any known mitigations. The maintainers will acknowledge a complete report within five business days and will coordinate remediation and disclosure in the private advisory.
If a credential may have been exposed, revoke it before sending the report and state only the credential type and affected scope. Never send the credential value.