Do not open a public issue for a suspected vulnerability or include customer data, credentials, webhook secrets, access tokens, or unredacted payloads in a report.
Use GitHub's private vulnerability report form. Include the affected code path, observed impact, and smallest safe reproduction.
There is no bug-bounty programme or guaranteed response time. Good-faith reports will be reviewed and handled as availability permits.