Do not open a public issue or Discussion for a suspected vulnerability. Use GitHub's private vulnerability reporting form. Include the affected version or commit, impact, minimal reproduction, and any known mitigations. Remove credentials, private datasets, personal information, and unrelated exploit material.
If private vulnerability reporting is unavailable, contact the repository owner through the email address on their GitHub profile and ask for a private reporting channel. Do not send exploit details until a private channel is confirmed.
Before the first stable release, security fixes target the latest published
0.x release and main. Older pre-release builds may require upgrading. The
project does not promise response or remediation times, but reports will be
triaged according to reproducibility, impact, and the safety of disclosure.
Public rendering bugs, accessibility problems, and non-sensitive denial-of- service cases should use the structured issue forms. When in doubt, report privately first.