This policy applies to every public repository under
github.com/Teknesyum that does not ship its own SECURITY.md.
Only the latest release of each project receives security fixes.
Do not open a public issue for a security problem.
Use GitHub private vulnerability reporting on the affected repository:
https://github.com/Teknesyum/<repository>/security/advisories/new.
If that form is unavailable, open an issue titled "Security contact request" without
details, and a private channel will be arranged.
Include what you did, what you expected, what happened, and the version or commit you tested. A working reproduction is worth more than a description of the symptom.
You will get an acknowledgement within seven days. Fixes are published as a normal release; coordinated disclosure is ninety days from the report, or sooner once the fix is out. Credit is given in the release notes unless you ask otherwise.