Report vulnerabilities privately. Do not open a public issue, post a proof of concept in a discussion, or share exploit details in a public channel before a fix is available.
Use the GitHub Security Advisory flow for private reporting. If that is not available to you, open a minimal issue that asks for a private contact channel and avoid including exploit steps, payloads, or secrets.
Provide:
- a short summary of the issue
- affected versions or commits, if known
- impact and attack surface
- reproduction notes, if safe to share
- any mitigation you have already identified
We aim to acknowledge reports promptly, triage them privately, and coordinate a fix before public disclosure. Severity, complexity, and release timing determine the exact response window.
Security fixes are expected to land through the normal review and CI path, then ship in a signed release tag after validation. Public advisories should name the fixed version only after the release is available.