Hello, I found a potential security issue involving untrusted project-controlled data being used in a Git command during incremental analysis. I have reproduced the behavior locally and prepared a minimal fix with regression coverage. The repository's SECURITY.md asks reporters to use private vulnerability reporting, but that option appears to be unavailable for this repository. Could a maintainer please provide a private channel so I can share the technical details and patch securely? I would be happy to be credited for the report and fix.
Hello, I found a potential security issue involving untrusted project-controlled data being used in a Git command during incremental analysis. I have reproduced the behavior locally and prepared a minimal fix with regression coverage. The repository's SECURITY.md asks reporters to use private vulnerability reporting, but that option appears to be unavailable for this repository. Could a maintainer please provide a private channel so I can share the technical details and patch securely? I would be happy to be credited for the report and fix.