Please report suspected vulnerabilities through GitHub private vulnerability reporting. Do not include credentials, private messages, user data or exploit details in a public issue.
Include the affected version or commit, platform, impact, and the smallest safe reproduction you can provide. Maintainers will acknowledge a report through the private advisory and coordinate disclosure after a fix is available. This project does not promise a fixed response or release timeline.
For ordinary bugs and feature requests that do not expose a security boundary, use the public issue tracker instead.