Security fixes target the latest released version. Please report vulnerabilities privately using GitHub security advisories. Include the affected version, a minimal reproduction and the expected impact. Do not place credentials or customer data in public issues.
Operational requirements and the dependency advisory review are documented in the production checklist.