Do not open a public GitHub issue for security vulnerabilities.
Report security concerns privately by opening a GitHub Security Advisory on this repository.
Include in your report:
- A description of the vulnerability and its potential impact.
- Steps to reproduce or a proof-of-concept (if applicable).
- The commit or branch where the issue was observed.
We will acknowledge receipt within 2 business days and aim to provide a fix or mitigation plan within 14 days for critical issues. You will be credited in the advisory unless you prefer to remain anonymous.