I would love some context from either parent commenter here. This is the first I've heard of security concerns with zig, though admittedly I don't use it much.
It's not really something I want to bring up again. I was asked my opinions on Zig, I gave them. The PR might not have been the 'best' solution but the vulnerability was left unaddressed - Andrew seems to insist I misunderstood something, but has failed several times to explain why.
I hope it's since been fixed, but panicking on UTF-8 decoding errors had the potential for massive damage in my opinion.