Security fixes are expected against the current public main branch.
Do not open a public issue with exploit details.
Preferred path:
- Use GitHub private vulnerability reporting for this repository if it is enabled.
- If that feature is unavailable, contact the maintainer through the repository owner's public GitHub profile and request a private reporting channel before sharing details.
Include:
- affected commit or branch
- reproduction steps
- impact
- any suggested mitigation
- reports will be reviewed by a human maintainer
- there is no guaranteed response-time SLA
- coordinated disclosure is preferred over public surprise disclosure