Please do not report suspected security vulnerabilities through public issues, discussions, or pull requests.
Use GitHub Private Vulnerability Reporting for this repository.
Include:
- the affected version or commit
- a description of the impact
- reproduction steps
- relevant logs or proof of concept, with secrets removed
If Private Vulnerability Reporting is unavailable, open a public issue only to request a private reporting channel. Do not include vulnerability details in that issue.
Maintainers will review reports as soon as practical and coordinate fixes and public disclosure when appropriate.