Please do not report security vulnerabilities through public GitHub issues.
Instead, use GitHub's private vulnerability reporting:
- Go to the repository's Security tab.
- Click "Report a vulnerability".
- Fill in the details (affected version, reproduction steps, impact).
Reports are delivered privately through GitHub — no email required. You will receive a response through the same channel, and any fix will be coordinated there before public disclosure.
This policy applies to all public repositories under this account unless a
repository defines its own SECURITY.md.