Please do not open public issues for security vulnerabilities.
- Preferred: use GitHub private vulnerability reporting for this repository (Security tab -> "Report a vulnerability")
- Alternate: open a private security advisory draft in this repository
Include the following details:
- affected component(s) and version/tag
- reproduction steps or proof-of-concept
- expected impact and scope
- any suggested mitigation
- Initial triage acknowledgement: within 3 business days
- Severity assessment + next action plan: within 7 business days
We coordinate responsible disclosure and will publish remediation details after a fix is available and users have had a reasonable upgrade window.