Please report suspected vulnerabilities privately, not in a public issue or pull request.
Use GitHub's private vulnerability reporting: open the Security tab of this repository and choose Report a vulnerability. If that is unavailable, contact the maintainer through the channel listed on their GitHub profile.
Please include:
- the affected version, commit, or file;
- a minimal reproduction or proof of concept;
- the impact you believe it has.
This project is maintained on a best-effort basis. No response time, acknowledgement, remediation, or fix is guaranteed, and no timeline or ETA is committed. Reports are reviewed as time allows.
Please give a reasonable private window before disclosing publicly. This is a request made in good faith, not an obligation owed in return, and it does not imply any commitment on the maintainer's part.
Security testing must target only your own local copy of this project. Do not test against, attack, or attempt to access any third-party or production system, any infrastructure you do not own, or any account that is not yours.