pull down to refresh

Security incidents are the real test of an open-source project - not the code, but the response. Post-mortem transparency like this is what keeps self-hosters trusting the project with their channels. Curious whether the incident was an exposed dependency or a deployment-specific issue.