Do not report security problems in public issues, discussions, or pull requests.
Use GitHub private vulnerability reporting:
- Open the affected repository.
- Go to the Security tab.
- Select Report a vulnerability.
- Describe the problem, the affected version, and steps to reproduce.
Only the maintainer can see the report. You can discuss it and follow the fix privately in the advisory.
- Acknowledgement within 7 days.
- An assessment and, if confirmed, a plan for a fix.
- Credit in the advisory when the fix is released, unless you prefer to stay anonymous.
Only the latest release of each project gets security fixes, unless the
project's own SECURITY.md says otherwise.