This project currently accepts security reports for the latest main branch.
Please do not open a public issue for sensitive vulnerabilities.
Use one of the following:
- Open a private security advisory on GitHub (preferred)
- Contact the repository owner directly on GitHub:
@Kfowever
When reporting, include:
- Affected component or file path
- Reproduction steps
- Impact assessment
- Suggested fix (if available)
- Initial triage target: within 7 days
- If confirmed, a patch or mitigation plan will be prepared as soon as possible
- Public disclosure is recommended only after a fix is available