Please report vulnerabilities in Z-Shell repositories privately:
- Open the affected repository's Security tab.
- Select Report a vulnerability to start a private GitHub Security Advisory.
- Include the affected repository and version or revision, the expected impact, and enough reproduction details for maintainers to evaluate the report. If you have a proposed fix, include or summarize it.
If Report a vulnerability is unavailable, use a private contact method on the Z-Shell organization profile. Do not include vulnerability details in a public issue, pull request, or discussion.
Maintainers will evaluate the report, coordinate any fix or mitigation, and keep the reporter informed. We will credit the reporter in the published record unless they request anonymity.
Please do not disclose the vulnerability publicly until a fix is published or the report is declined. Coordinate disclosure timing with the incident owner.
Maintainers follow the security incident response runbook for triage, remediation, disclosure, and post-incident review.