We take security reports seriously and ask that they be disclosed privately so a fix can ship before the issue is public.
Please do not open a public issue for security vulnerabilities.
Report privately through GitHub's private vulnerability reporting: open the repository's Security tab and choose Report a vulnerability. This creates a confidential channel visible only to you and the maintainers.
If you cannot use GitHub's private reporting, contact a maintainer directly and
ask for a private channel before sharing details. Maintainers are listed in the
PDP-Connect governance config
(and, for repos that keep one, in that repo's MAINTAINERS.md).