Do not post exploit details, credentials, personal information, or sensitive infrastructure data in public issues or pull requests.
If the repository's Security tab offers Report a vulnerability, use that private reporting channel. Otherwise, contact the repository owner through an existing trusted private channel. If you have no private channel, open an issue asking only for a private security contact, without disclosing the vulnerability.
Include the affected repository/version, impact, reproducible steps in an authorized test environment, and suggested mitigation. Remove secrets from attachments. No acknowledgement or remediation deadline is guaranteed for these personal projects.
Unless a repository publishes its own support policy, only its current maintained default branch is considered for fixes. Experimental and archived projects may have no active support.
Revoke or rotate exposed credentials immediately, assess usage and access logs, and notify the owner privately. Deleting the latest file does not remove secrets from Git history. Coordinate any history cleanup and affected clones before proceeding.
Security testing requires explicit authorization and a defined scope.