Please do not disclose suspected vulnerabilities publicly in issues, discussions, pull requests, blog posts, or social media.
Report security concerns privately via the canonical request path:
Include:
- repository name;
- affected version or tag;
- reproducible steps;
- expected vs actual behavior;
- impact summary.
This public repository is an evaluation surface. Public reports should avoid sharing secrets, credentials, private keys, internal endpoints, server details, private deployment mechanics, or other sensitive implementation details.
Reports are reviewed privately. Validation, response timing, and remediation decisions depend on severity, reproducibility, and scope.
If you are unsure whether a detail is sensitive, do not publish it publicly. Use the private reporting path first.