Please do not report security vulnerabilities through public GitHub issues, pull requests, or discussions.
Report suspected vulnerabilities privately by email:
Please include enough information to reproduce and assess the vulnerability, such as:
- A description of the vulnerability.
- Steps to reproduce or a proof of concept, when safe to provide.
- The affected project, version, or commit.
- The potential impact.
- Any relevant logs or supporting information.
You may encrypt sensitive information if appropriate.
We will review security reports and follow up when additional information is required.
Please allow reasonable time for investigation and remediation before publicly disclosing a vulnerability.