This repository is a template. Security fixes apply to the current main branch.
Outcome: a private report that maintainers can reproduce and triage without exposing the issue publicly.
- Open GitHub private vulnerability reporting. Do not create a public issue.
- Include the affected revision, reproduction steps, expected impact, and any suggested fix.
- Submit the report.
Reporting is complete when GitHub creates the private security advisory. We triage the report and coordinate fixes through that advisory.