Do not place credentials, personal data, private configuration, or exploit details in a public issue.
Use GitHub's private vulnerability reporting or security-advisory feature when it is available for this repository. If private reporting is unavailable, open a minimal public issue stating that a private security report is needed, without including sensitive details.
Security fixes target the current default branch. Reference and demonstration code must be reviewed and adapted before production use.
Never commit environment files, access tokens, OAuth credentials, private keys, tenant or account identifiers, production datasets, contact lists, or client/employer configuration.