Security fixes target the latest published release and the main branch unless
a maintainer explicitly documents additional supported versions.
Please report suspected vulnerabilities to security@techsquidtv.com or
through GitHub private vulnerability reporting or a draft security advisory:
https://github.com/techsquidtv/canvas-timeline/security/advisories/new
Do not open a public issue for an unpatched vulnerability. Include the affected package, affected version or commit, reproduction steps, and the expected impact.
Maintainers aim to acknowledge reports within 7 days. Confirmed vulnerabilities will be triaged for severity, fixed on a private branch when appropriate, and published with release notes once a fix is available.