Do not disclose vulnerabilities, credentials, or sensitive reproduction data in public issues or pull requests.
Use GitHub's private vulnerability reporting form. You can also find Report a vulnerability on this repository's Security page.
A private report should include:
- The affected commit or version and relevant environment.
- Reproduction steps or a minimal proof of concept.
- Expected and observed behavior, impact, and required access.
- Redacted logs or screenshots when useful. Do not include live credentials or other people's data.
Test only systems and data you are authorized to access. The project is under development and does not currently publish a supported-version matrix or response-time commitment.