Security and integrity fixes are applied to the latest revision of the default branch. Older snapshots and downstream copies are not supported.
Use GitHub's private vulnerability reporting for suspected malicious files, compromised automation, leaked credentials, or other security-sensitive concerns.
Do not disclose a vulnerability in a public issue before maintainers have had a reasonable opportunity to investigate it. Include reproduction details, impact, affected files or revisions, and any proposed mitigation.
Electrical, mechanical, or manufacturing errors that do not involve a security concern should be reported with the component issue form.