Security fixes target the latest release and the current main branch.
Do not open a public issue for a vulnerability or include real sessions, credentials, private learning data, or absolute user paths in a report.
Use GitHub's Report a vulnerability link in the repository Security tab. Include the affected version, impact, minimal reproduction, and any suggested mitigation using synthetic data only. If private vulnerability reporting is temporarily unavailable, contact the repository owner through the private contact options on their GitHub profile.
You should receive an initial acknowledgement within seven days. Release timing depends on severity, reproducibility, and the upstream DSH version involved.