Security fixes are released for the latest published version of the SDK. Users should upgrade to the newest release before reporting an issue that may already be fixed.
Do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting and include the affected version, impact, reproduction steps, and any suggested remediation.
We will acknowledge the report, investigate it privately, and coordinate disclosure after a fix is available.