Do not disclose a suspected vulnerability in a public issue, discussion, or pull request.
Use the affected repository's Security tab and choose Report a vulnerability when private vulnerability reporting is available. Include:
- the affected repository, version, commit, or release;
- steps to reproduce;
- the potential impact;
- any suggested mitigation;
- whether the report includes sensitive or personal data.
If private vulnerability reporting is unavailable, open a non-sensitive issue asking the maintainer to establish a private reporting channel. Do not include exploit details in that issue.
Security support follows the lifecycle state documented by each repository. Archived and superseded projects may receive documentation-only advisories instead of code fixes.