Security fixes are applied to the latest version on the default branch.
Use the affected repository's private vulnerability-reporting feature. Do not open a public issue or pull request for a suspected vulnerability.
Include a clear description, reproduction steps using fabricated data, likely impact, and any suggested mitigation. Never include client, taxpayer, employee, payroll, access-token or other sensitive data.
We will acknowledge a valid report within seven days and coordinate the fix and disclosure timeline with the reporter.
If a repository has its own SECURITY.md, that repository-specific policy
takes precedence over this account-level default.