Do not open a public issue or include vulnerability details in a pull request.
Report the vulnerability privately through GitHub Security Advisories. If that route is unavailable, contact a repository maintainer through an existing private channel and ask for a secure reporting route before sharing sensitive details.
- the affected version or commit
- reproduction steps
- potential impact
- any known mitigation
Remove credentials, personal health data, and other sensitive information from the report.
Security fixes target the current main branch. Update any pre-release or
TestFlight installation to the most recent available build before retesting a
report.
Allow maintainers time to investigate and release a fix before sharing the vulnerability publicly. Coordinate disclosure through the private advisory.