Please do not report security vulnerabilities through public GitHub issues.
Use the repository's Security tab and its private vulnerability reporting option when it is available. Otherwise, contact the repository maintainers privately through GitHub with:
- a description of the vulnerability;
- affected versions or commits;
- steps to reproduce or a proof of concept;
- potential impact; and
- any suggested remediation.
We will acknowledge reports, investigate them, and coordinate a fix before public disclosure where practical.
Supported versions vary by repository. Check the repository README and releases for the maintained version.