Do not report security vulnerabilities through public GitHub issues.
Instead, please report them via GitHub's private vulnerability reporting:
- Go to the Security tab of this repository
- Click "Report a vulnerability"
Include the following information:
- Type of vulnerability
- Full paths of affected source files
- Step-by-step reproduction instructions
- Impact assessment
- Initial response: Within 7 days
- Resolution target: Within 30 days
- We will acknowledge receipt of your report
- We will confirm the vulnerability and determine its impact
- We will release a fix and publicly disclose the issue