Until 1.0, the latest published minor line receives security fixes. Older 0.x
lines may require upgrading because the API and physical schema are
experimental.
Do not file public issues for suspected vulnerabilities. Use the repository's GitHub private vulnerability-reporting flow.
Include the affected version or commit, deployment conditions, reproduction, impact, and any proposed mitigation. Maintainers should acknowledge a report within three business days, provide a status update within seven, coordinate a fix and advisory, and credit the reporter unless anonymity is requested.
Never include production D1 credentials, tokens, customer data, or destructive proofs of concept in a report.