Do not open a public Issue for a suspected vulnerability.
Use the Security tab in the affected repository to open a private GitHub Security Advisory. Include the affected version, impact, reproduction steps, and any suggested mitigation. Remove credentials and unrelated personal data from the report.
If private vulnerability reporting is unavailable, contact @loulanyue through a
private method listed on the maintainer's GitHub profile and identify the affected
repository. Please allow a reasonable remediation window before public disclosure.
Security support applies to actively maintained versions identified in the target repository's releases or security policy. Archived repositories and unsupported versions may receive documentation or migration guidance instead of a patch.