Do not report security vulnerabilities through public GitHub Issues, Discussions, pull requests, or other public channels.
Use GitHub's private vulnerability reporting for this repository instead:
- Open the repository's Security tab.
- Open Advisories.
- Choose Report a vulnerability.
Include enough evidence to reproduce and assess the issue, such as:
- the affected component, path, or workflow;
- reproduction steps;
- the observed security impact;
- relevant commit or deployment information, when known;
- a suggested mitigation, when available.
Do not include live credentials, access tokens, private keys, or unnecessary personal data in the report. Use redacted or test values where possible.
Keep vulnerability details private while they are being reported and assessed. Do not publish exploit details, credentials, or reproduction material through public repository channels.