Security issues should be reported against the latest version of the project.
Please do not publicly disclose sensitive security issues before they have been reviewed.
Report vulnerabilities privately to the project maintainer with:
- A description of the issue.
- Reproduction steps.
- Affected component.
- Relevant logs or proof of concept.
- Suggested mitigation, if available.
Please do not include passwords, private keys, tokens, or other secrets in reports.