If you find a security issue, please do not open a public issue with sensitive details.
Use GitHub's private vulnerability reporting when it is enabled for the repository. If private reporting is not available, contact the repository owner directly with:
- The affected repository and branch.
- A clear description of the issue.
- Steps to reproduce.
- Impact and any suggested mitigation.
Unless a repository states otherwise, only the default branch is actively maintained.
Security reports are handled with responsible disclosure. The goal is to confirm, fix, and communicate issues without exposing users or systems to unnecessary risk.