Only the latest released version of Splat.DependencyInjection.SourceGenerator on
NuGet is supported.
Fixes ship in a new release; no patches are issued for earlier versions. Upgrade to the latest
version before reporting an issue.
Report vulnerabilities through GitHub private vulnerability reporting:
Do not open a public issue, pull request, or discussion for a security report.
Include the package version you tested, the target framework and Roslyn/SDK version, steps to reproduce, and the impact you believe it has. A minimal reproduction project is the most useful thing you can attach.
You will get an acknowledgement on the advisory thread, and updates there as the report is triaged and fixed. Once a fix is released the advisory is published with credit to the reporter unless you ask otherwise.