Until Trillium reaches 1.0, only the most recent release will be certainly be supported for security updates, but an effort will be made to backport critical patches when possible.
To report a vulnerability, either email [email protected], send a twitter dm to @jacobrothstein, or try smoke signals from distant mountains