We take security bugs seriously. Please report vulnerabilities responsibly.
Do not report security issues in public GitHub issues or discussions.
To report a security vulnerability, use GitHub's Security Advisories (“Report a vulnerability” on the Security tab).
Include as much of the following as you can:
- Description of the issue and affected area
- Steps to reproduce
- Impact and possible fix (if you have one)
We will acknowledge your report and keep you updated on progress and any fix.
- We will address issues as quickly as we can.
- We will credit you in the advisory unless you prefer to stay anonymous.
- Please avoid public disclosure until a fix has been released or we agree on a timeline.