We take security bugs seriously and appreciate responsible disclosure. Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, report them privately with one of these two methods. Report them through GitHub Security Advisories. This is the preferred method, and it uses the private vulnerability reporting feature of GitHub. You can also email one of the maintainers directly. Maintainer contact details are on their GitHub profiles.
Please include as much of the following information as possible to help us triage your report:
- A description of the vulnerability and its potential impact.
- Steps to reproduce, or a proof-of-concept.
- The affected version(s), if known.
We will acknowledge your report as soon as possible and keep you informed as we work on a fix.