Report vulnerabilities through the affected repository's private GitHub security advisory form (Security tab → Report a vulnerability). Do not open public issues, discussions, or pull requests for unpatched vulnerabilities.
Include: affected repository and version or commit, reproduction or configuration, impact assessment, and any known mitigations.
This organization maintains multi-product shared libraries, mostly under source-available (FSL) licenses. Credentials, private deployment details, customer data, and secrets are out of scope and must never be included in reports or reproductions.
Reports are triaged in arrival order. Fixes ship as new versions with release notes describing the impact and upgrade path. Credit follows the reporter's preference.