Security fixes apply to the latest commit on main.
Do not open a public issue for a suspected vulnerability.
Use GitHub's private vulnerability reporting for this repository.
If GitHub private reporting is unavailable, open a public issue titled Private security contact request without technical details or private data. The maintainer will establish a private channel before accepting the report.
Include:
- A concise description of the affected boundary
- Reproduction steps using synthetic data
- Expected and observed behavior
- The smallest safe proof of impact
- A suggested mitigation, if known
- Real company evidence
- Credentials or private endpoint names
- Production database identities
- Private evaluation questions
- Backups, manifests, or deployment receipts
- Personal information
A report does not need private data to prove that a public contract or reference implementation is unsafe.
The maintainer will acknowledge a valid report, assess severity, and coordinate a fix before public disclosure when practical.