Do not disclose suspected vulnerabilities in a public issue, discussion, or pull request. For public repositories, use the repository's Security tab and select Report a vulnerability when that option is available. For a private repository, contact a repository administrator through an existing private channel.
Include the affected repository and version, reproduction steps, expected impact, and any suggested mitigation. Remove credentials, customer data, and other secrets from the report.
Maintainers will acknowledge a report, assess its severity, coordinate a fix, and publish an advisory when disclosure is appropriate. Do not test against production systems or access data that does not belong to you.