Please do not open public issues for sensitive security reports.
Instead, report vulnerabilities privately through GitHub Security Advisories (if enabled) or contact the maintainer directly via the channels listed on the repository profile.
Include:
- A clear description of the issue.
- Reproduction steps or proof of concept.
- Potential impact and affected files/sections.
- Initial acknowledgment: within 7 days.
- Triage and risk assessment: as soon as possible based on severity.
- Mitigation or fix communication: after validation.