Security fixes target the latest code on the default branch and the latest release, when releases are available.
Do not report security vulnerabilities in a public issue.
- Open the Security tab of the affected repository and use Report a vulnerability if that option is available.
- Otherwise, contact the maintainer privately using a contact method listed on the NEDONION profile before sharing sensitive details.
Include the affected repository, version or commit, impact, reproduction steps, and any suggested mitigation. Remove secrets and personal data from reports. If a credential may have been exposed, revoke or rotate it immediately.
Reports are reviewed on a best-effort basis. This policy does not promise a response time or bug bounty.