Only the latest code on the default branch is considered supported for security fixes.
Please report vulnerabilities privately through GitHub Security Advisories. Do not open a public issue for an undisclosed vulnerability.
When reporting a security issue, include:
- affected component or file path
- reproduction steps
- expected impact
- whether secrets, infrastructure, or user data may be exposed
- CodeQL analysis
- dependency review on pull requests
- secret scanning with Gitleaks
- Dependabot update automation
- Scorecards analysis
- strict code review ownership via CODEOWNERS