Do not open a public issue for a security vulnerability.
Report it privately through the affected repository's GitHub private vulnerability reporting form, under that repository's Security tab. If the repository has not enabled private reporting, or the issue spans more than one repository, open a private report against camsai/governance instead.
Please include what the issue is, which repository and version it affects, and how to reproduce it.
A CAMSAI maintainer will acknowledge your report and work with you on a fix and a disclosure timeline. We will credit you when the fix is published, unless you prefer otherwise. Please give us a reasonable opportunity to release a fix before disclosing publicly.
Every CAMSAI project is required to document a way to report a vulnerability privately; see project intake, section 7.