Security fixes are made on the default branch and included in the next ProPR release. Operators should run the latest published release; older releases do not receive separate security patches.
Please do not open a public issue or pull request for a suspected vulnerability.
Use GitHub's private vulnerability reporting flow instead:
- Open the repository's Security tab.
- Select Advisories and then Report a vulnerability.
- Include affected versions or commits, impact, reproduction steps, and any suggested mitigation you have identified.
Reports are visible only to repository maintainers and the reporter while they are being investigated. Maintainers will acknowledge the report, validate its impact, coordinate a fix and release, and agree on disclosure timing with the reporter. Please avoid testing against systems or data you do not own or have explicit permission to assess.
For configuration questions, hardening advice, or bugs without a security impact, use the repository's normal issue tracker.