Do not disclose exploitable details, credentials, tokens, private keys, recovery codes, device secrets, or personal data in a public issue.
Use GitHub's private vulnerability reporting for the affected repository when that option is available. If private reporting is not available, open a minimal public issue requesting a private security contact channel and do not include technical exploit details until a private channel is established.
Security reports are particularly relevant when they involve:
- authentication or authorization bypass;
- exposure of credentials or secrets;
- unsafe command execution;
- unintended network access;
- privilege escalation;
- insecure update or release mechanisms;
- data leakage;
- unsafe device-control behavior.
Provide the smallest reproducible description necessary to validate the issue, including affected version, environment, impact, and reproduction conditions. Do not test against systems or devices you do not own or have permission to test.
Repository-specific security policies override this default document.