Security reports should be handled privately. Do not publish undisclosed vulnerabilities in public issues or include real credentials, tokens, private URLs, or user data in a report.
Contact the maintainer through Diwas Khatri with the affected repository, version or commit, reproduction steps, impact, and mitigation details. Each project may define additional security requirements in its own repository.