If you discover a vulnerability, please do not open a public issue.
- Report it privately to the project maintainers (preferred: GitHub Security Advisory if enabled).
- Include:
- What you observed
- Steps to reproduce
- Affected versions / configuration
- Suggested fix (if you have one)
We will acknowledge receipt and work with you to coordinate a fix.