Security fixes are applied to the latest commit on the default branch. Garden does not currently maintain older release lines.
Use this repository's Security tab to submit a private vulnerability report through GitHub Security Advisories. Include affected paths, reproduction steps, impact, and any proposed remediation.
Do not open a public issue for an unpatched vulnerability and do not include live credentials, session cookies, customer data, or other secrets in a report. If a credential may have been exposed, revoke it before sharing redacted evidence.
The maintainers will acknowledge a complete report, investigate it, and coordinate disclosure after a fix is available. Timelines depend on severity and reproducibility.