If you discover a security issue, accidental leak, or exposure of private assets, report it through the private channel used by the repository owners.
Please include:
- A short description of the issue.
- The files or folders involved.
- The potential impact.
- Any reproduction steps, if applicable.
- Unauthorized access to private assets.
- Accidental inclusion of sensitive or restricted files.
- Malicious or unexpected executables.
- Integrity issues affecting published assets.
We will review reports promptly and decide on containment, removal, or replacement as needed.
Do not publicly disclose a security issue until the maintainers have had a chance to respond.