Please report suspected security vulnerabilities privately using GitHub's Private Vulnerability Reporting feature.
Do not create a public GitHub issue, pull request, discussion, or other public channels for a suspected security vulnerability.
Please provide enough information to reproduce and understand the issue, including affected functionality, steps to reproduce, and any relevant technical details.
Security reports will be reviewed and investigated on a best-effort basis. We will make reasonable efforts to acknowledge and address legitimate security issues and will communicate with the reporter as appropriate.
Please allow reasonable time for investigation and remediation before publicly disclosing a vulnerability.
When appropriate, disclosure will be coordinated with the reporter after a fix or mitigation is available.
Security researchers who responsibly report vulnerabilities may be credited for their contribution, with their permission.