Do not report vulnerabilities in public issues.
Use the affected repository's Security tab to open a private vulnerability report or draft security advisory. Include the affected version, impact, reproduction steps, and any suggested mitigation.
We aim to acknowledge reports within five business days and coordinate fixes and disclosure with the reporter. Only the latest released major version and the default branch are supported unless a repository documents otherwise.