If you find a security vulnerability, do not open a public issue.
Send a private report via:
- GitHub Security Advisories — navigate to the repo's Security tab and create a new advisory.
- Direct message — contact the maintainer at @ForgedEmir.
You should receive a response within 48 hours.
- Description of the vulnerability
- Steps to reproduce (PoC preferred)
- Potential impact
We believe in coordinated disclosure. Please give us reasonable time to fix the issue before publishing it publicly.