Please do not report a vulnerability in a public issue, discussion, pull request, or comment.
Use the repository's Security → Advisories → Report a vulnerability form. If that form is unavailable, open an issue that only asks the maintainer to enable a private reporting channel. Do not include vulnerability details in that issue.
Before submitting any report:
- Remove API keys, tokens, passwords, cookies, authorization headers, and signing material.
- Remove personal data, unpublished manuscripts, private source material, machine names, usernames, and absolute filesystem paths.
- Share only the smallest redacted reproduction. Do not attach complete logs, HAR files, crash dumps, configuration directories, or project archives.
- Revoke or rotate any credential that may already have been exposed.
Reports are assessed according to impact and reproducibility. Please allow the maintainer time to investigate before public disclosure.