Note
On this page, report a vulnerability without exposing customer data, credentials, or an exploitable issue publicly.
No public production version has been promoted yet. Security fixes target the current main development line until the changelog lists supported releases.
Use the repository host's private security advisory feature. Include the affected version, impact, safe reproduction steps, and a proposed fix if available. Remove access tokens, org IDs, usernames, CSV contents, and sensitive field values.
Maintainers will acknowledge a complete report, assess severity, coordinate a fix and release, and credit the reporter when requested. Do not open a public issue before a fix is available.
See Security and access for the product boundary.