Do not open a public issue, discussion, or pull request for a suspected vulnerability, leaked credential, private-data exposure, or unreleased-content disclosure.
Use the affected repository's Security tab to submit a private vulnerability report or draft private security advisory. Include:
- the affected repository, revision, version, or release;
- a clear description of the impact and affected boundary;
- minimal reproduction steps or evidence;
- whether exploitation or disclosure is known to have occurred; and
- a safe way to coordinate follow-up through GitHub.
Do not include real credentials, unnecessary personal data, or additional private creative context. If GitHub's private reporting interface is unavailable, contact an organization owner through an established private Studio channel and share only enough information to establish a secure reporting path.
Maintainers will acknowledge a valid private channel as soon as practical, triage severity and exposure, preserve evidence, and coordinate remediation and disclosure. Timelines depend on impact and complexity. Do not disclose the issue publicly until maintainers confirm that affected users and releases are ready.
Each releasing repository documents its supported versions. Unless it states otherwise, only the latest release and the current default branch are eligible for security fixes.