Security fixes are intended for the default branch and current development work. Use the latest commit or tagged release when deploying.
Please report security issues privately so they can be fixed before broad disclosure.
- If the GitHub repository has private vulnerability reporting enabled, use Security → Report a vulnerability (or the equivalent advisory flow).
- Otherwise, contact the repository maintainers through a private channel they publish (for example an email address in the GitHub organization or user profile).
Do not open a public issue for an undisclosed vulnerability.
- A short description of the impact and affected components
- Steps to reproduce or proof-of-concept, if you can share them safely
- Your preferred disclosure timeline, if any
Maintainers will acknowledge receipt when possible and coordinate a fix and release timeline with you.