Do not report security vulnerabilities through public GitHub issues.
For security-sensitive reports, contact the repository maintainers or SAGE organization owners through the security contact listed in the relevant repository. Include:
- The affected repository and version or commit.
- A clear description of the issue.
- Reproduction steps or proof-of-concept details, when safe to share.
- Known impact on users, deployments, data, credentials, tools, or services.
Maintainers should acknowledge security reports promptly and coordinate responsible disclosure before public discussion.