Supported version: the latest release of chad-code on PyPI. chad is single-user;
a fix ships as a new release, not as a backport.
Reporting a vulnerability: report privately via GitHub Security Advisories — the "Report a vulnerability" button on the repo's Security tab — not a public issue.
CodeQL and a dependency audit already run in CI on every push
(.github/workflows/codeql.yml, .github/workflows/security.yml).