Please don't open a public issue for security problems.
Report it privately through GitHub: open the affected repository, go to the Security tab, and choose Report a vulnerability. Only maintainers can see the report.
Please include the affected repo and version, the steps to reproduce, and the impact you observed.
- We acknowledge reports within 3 working days.
- We send an initial assessment within 7 days.
- We keep you updated until it's fixed, and we credit you in the release notes unless you'd rather stay anonymous.
Unless a repository says otherwise, only the latest release receives security fixes.