Please do not disclose suspected vulnerabilities in a public issue, discussion, pull request, or commit.
Use the repository's Security tab and select Report a vulnerability when private vulnerability reporting is available. Include:
- affected repository and version, branch, or commit;
- a clear description of the issue and potential impact;
- safe reproduction steps or proof of concept;
- any suggested mitigation;
- whether the issue is already public.
If a private reporting option is not available, do not publish exploit details. Contact the repository owner through the private contact method shown on the GitHub profile.
Do not include live credentials, unrelated personal data, or destructive test results. Test only systems and data you are authorized to access.
Reports are prioritized according to severity and reproducibility. Please allow time for validation and remediation before public disclosure. No repository should be treated as production-ready solely because it contains a security policy.