Do not open a public issue for a security problem.
Report it through GitHub's private vulnerability reporting instead: open the repository's Security tab, then Report a vulnerability. This sends the report to the maintainers only, not to the public issue tracker.
Include what you can:
- The package and version affected.
- Steps to reproduce the problem.
- The impact you expect it to have.
This project has not shipped a 1.0 release yet. Until then, security fixes
land on the latest published version of each package. See
_docs/plan.md for the current release status.
A maintainer will acknowledge a report and follow up with next steps. Response
time is best-effort while this project is pre-1.0.