Please do not open a public issue for a security vulnerability.
The preferred way to report a vulnerability is through GitHub's private vulnerability reporting, if it's enabled on the repository:
- Go to the repository's Security tab.
- Click Report a vulnerability.
- Fill in as much detail as you can — affected versions, steps to reproduce, and potential impact.
If private vulnerability reporting isn't enabled on a given repository, email g.orofino@protonmail.com instead, with the same details.
- Acknowledgement of your report within a few days.
- An assessment of severity and, if confirmed, a fix timeline.
- Credit in the release notes once fixed, unless you'd prefer to stay anonymous.
Unless a repository's own SECURITY.md says otherwise, only the latest released version of a project is supported with security fixes.