Please do not file an issue on GitHub, or send a PR addressing the issue.
Most recent major version only.
Contact one of the maintainers directly:
You can report vulnerabilities on GitHub too: https://github.com/varvet/pundit/security
Thank you!