Please do not open a public issue for security vulnerabilities.
Until a dedicated security contact is published, report sensitive issues privately to the maintainers through the repository contact channel.
When reporting a vulnerability, please include:
- A clear description of the issue
- Steps to reproduce
- Potential impact
- Any suggested mitigation if available
We will acknowledge valid reports as quickly as possible and work on a fix before public disclosure whenever feasible.