Report a vulnerability privately through GitHub's Security → Report a vulnerability flow for this repository. Do not open a public issue for an exploitable problem.
Synopsis treats analyzed repositories as untrusted input: it does not restore, compile, load, or execute their code. Security reports involving HTML injection, unsafe source links, unintended file traversal, or execution of analyzed content are especially important.