RPL is currently pre-1.0. Security fixes are applied to the latest version on the main branch.
Do not open a public issue with vulnerability details.
Use GitHub's private Report a vulnerability form in the repository's Security tab. Include:
- the affected version or commit;
- what an attacker could do;
- clear steps to reproduce the problem; and
- any suggested fix, if you have one.
If the private form is unavailable, open a public issue that asks the maintainer to enable private reporting. Do not include sensitive details in that issue.