Please do not disclose an unpatched vulnerability in a public issue, pull request, discussion, or chat.
Report it through the repository's Security tab, under Report a vulnerability. The draft advisory it opens is visible only to maintainers.
Include the affected version or commit, platform, impact, reproduction steps, and a minimal proof of concept. Remove API keys, personal data, transcripts, recordings, and other secrets before submitting.
There is no promise of a fixed response or remediation time until a supported release and disclosure process are established. Maintainers should update this document with supported versions and a coordinated disclosure timeline before the first public release.
For ordinary bugs and feature requests, use the issue templates instead.