Do not open a public issue for a suspected vulnerability, exposed credential, or privacy concern.
Use GitHub's private vulnerability reporting flow from the repository's Security tab. Include the affected version or commit, reproduction steps, impact, and any suggested remediation. Do not include real API keys, user data, or paid-media inputs in the report.
If a credential may have been exposed, revoke or rotate it before sharing diagnostic details. Replace the value with a redacted identifier and report only the credential type and affected environment.
Security fixes are applied to the latest released version and the current default branch. Older releases may require upgrading before a fix is available.