Security fixes are accepted against the latest release and the default branch.
Do not open a public issue for vulnerabilities. Use GitHub Security Advisories or email security@moderately.ai with impact, reproduction steps, and the affected version or commit.