Please do not put credentials, private data or a working exploit against a live service in a public issue.
Use GitHub's private vulnerability reporting when available. Otherwise email shivam.work.eml@gmail.com with the repository name, affected version, a minimal reproduction and the likely impact. Share only the information needed to investigate.
This is an independently maintained collection of projects. There is no guaranteed response time or formal vulnerability-reward program.
If a credential has been committed, deleting the current file does not invalidate it or remove earlier copies. Revoke or rotate it with the provider, update the deployment's secret configuration, and then assess whether history cleanup is required. Do not test a discovered key against someone else's service.