Please report security vulnerabilities privately, not in public issues.
- Preferred: open a private report via the repository's Security → Report a vulnerability tab (GitHub Private Vulnerability Reporting).
- Alternatively, email boss@cezaraugusto.net with details and reproduction steps.
You can expect an initial acknowledgement within a few days. Once a fix is released, the advisory will be published and credited.
These are small, independent libraries. Security fixes are applied to the latest published version of each package; please upgrade to the latest release.