Do not include suspected vulnerability details in a public issue.
Use GitHub's private vulnerability reporting flow when the repository's Security page shows Report a vulnerability. The form creates a private report for the repository maintainers. GitHub documents the process in Privately reporting a security vulnerability.
If Report a vulnerability is unavailable, open a public issue containing only a request for a private reporting channel. Do not include security-sensitive details in that issue. This project does not publish an alternative security contact address.
Please include enough private detail to reproduce and assess the report:
- affected commit or version;
- prerequisites and impact;
- a minimal reproducer or failing test, when safe to share; and
- any suggested remediation or embargo constraints.
This experimental verification harness has no bug-bounty program or response-time service-level agreement.