Please do not open a public issue for an unpatched vulnerability.
Use GitHub's private vulnerability reporting for this repository. Include:
- Affected component and version
- Reproduction steps or proof of concept
- Expected impact
- Suggested mitigation, if known
The maintainer will acknowledge valid reports and coordinate disclosure after a fix is available.
Security fixes target the latest release on the main branch.
Never include API keys, tokens, private screenshots, customer data, or exploit details in public issues.