Do not open a public issue containing API keys, subscription tokens, receipts, customer data, private endpoints, logs with identifiers, or security exploit details.
Use GitHub's private security advisory feature for vulnerability reports:
Security > Advisories > New draft security advisory
Include affected version, impact, reproduction steps with fake data, and a proposed mitigation when available. Remove all personal and customer information before attaching logs or screenshots.
Supported security fixes target the latest released version. Review the public Privacy Policy and open-source data boundaries before reporting or publishing diagnostic material.