Thanks for helping keep these projects and their users safe.
Unless a project's own SECURITY.md states otherwise, only the latest
released version on the default branch receives security fixes. Please make
sure you can reproduce any issue against the most recent release before
reporting it.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, report them privately through GitHub's built-in private vulnerability reporting:
- Go to the Security tab of the affected repository.
- Click Report a vulnerability (under Advisories).
- Fill out the form with as much detail as you can.
If a repository does not show the Report a vulnerability button, private reporting has not been enabled there yet — please do not disclose the issue in a public issue, pull request, or discussion. Instead, contact the maintainer privately via their GitHub profile so a secure channel can be arranged.
Maintainers: enable private vulnerability reporting on every repository so reporters always have a secure, low-disclosure path.
To help us triage quickly, please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce (proof-of-concept code, requests, or configuration)
- Affected version(s), and the environment you observed it in
- Any suggested remediation, if you have one
- Acknowledgement of your report within a few days.
- An initial assessment and, where relevant, a request for more information.
- Coordinated disclosure: we will work with you on a timeline and credit you in the advisory once a fix is available, unless you prefer to remain anonymous.
Please act in good faith, avoid privacy violations and service disruption, and give us reasonable time to address the issue before any public disclosure.