Do not report security vulnerabilities through public GitHub issues.
Use GitHub Security Advisories to send a private report. Include the affected version, impact, reproduction steps or a proof of concept, and any suggested mitigation. Remove production credentials, kubeconfigs, tokens, and Kubernetes Secret values from all attachments.
The maintainers will acknowledge the report, investigate it, and coordinate disclosure after a fix is available.
Security fixes are provided for the latest released version. Confirm the issue against the latest release before reporting it when feasible.