Meta takes the security of our software products and services seriously, including all of the open source code repositories managed through our GitHub organizations.
If you believe you have found a security vulnerability in this repository, please report it through our bug bounty program rather than filing a public issue. Meta has a bounty program for the safe disclosure of security bugs. Please go through the process outlined on that page.
Please do not report security vulnerabilities through public GitHub issues, pull requests, or discussions.