Do not disclose vulnerabilities in public issues. Use GitHub's private Security > Report a vulnerability flow for this repository. Include affected versions, impact, a minimal reproduction, and suggested mitigations without including live credentials or customer data.
Maintainers should acknowledge a complete report within five business days, coordinate remediation and disclosure with the reporter, and publish an advisory when users need to take action. No bounty or response-time guarantee is implied.
Security fixes are applied to the latest release on main. Users should upgrade to the newest published version. Never submit production secrets in reports, logs, tests, or pull requests; rotate any credential that may have been exposed.