Please do not open a public issue for a suspected vulnerability.
Use the repository's Security tab and select Report a vulnerability to send a private report. Include the affected version or commit, impact, reproduction details, and any suggested mitigation.
If private vulnerability reporting is unavailable, contact the repository owner through their GitHub profile without publishing exploit details.
You can expect an initial acknowledgement within seven days. Timelines for validation and remediation depend on severity, project maturity, and maintainer availability. Please allow a reasonable remediation window before disclosure.
Only supported versions identified by the individual repository are eligible for security fixes. Experimental and archived repositories may not receive patches.