All of our public non-archived repositories are supported with security updates.
To report a security vulnerability, please send it to [email protected]. If a patch is not available, we may share that vulnerability through GitHub's reporting features; otherwise, we will communicate fixes in our release notes after they're remediated.