Security fixes are applied to the latest main branch.
Do not open a public issue for a security vulnerability.
Report vulnerabilities privately to the repository owner through GitHub's private vulnerability reporting or the maintainer's GitHub profile contact mechanism.
Include:
- a clear description of the issue
- affected files or endpoints
- reproduction steps
- potential impact
- a proposed mitigation when available
Do not include API keys, tokens, credentials, or private incident data in reports.