Please do not report suspected security vulnerabilities in a public issue, discussion, pull request, or comment.
If this repository has GitHub's private vulnerability reporting enabled, use Report a vulnerability from the repository's Security area.
If private vulnerability reporting is not available, open a public issue titled Security contact request without including technical details of the vulnerability. I will arrange a private way to continue the conversation.
When reporting a vulnerability privately, please include whatever information is available, such as:
- A description of the issue and its potential impact
- The affected version, file, feature, or component
- Steps or a proof of concept that reproduce the issue
- Any known workarounds or mitigations
Please avoid accessing, modifying, or exposing other people's data while investigating a potential vulnerability.
Unless a repository states otherwise, security fixes are generally targeted at the current release or current version of the project.
Older releases may not receive security updates.
Please allow reasonable time to investigate and, where appropriate, prepare a fix before publicly disclosing a reported vulnerability.
Thank you for reporting security issues responsibly.