Security fixes are prioritized for the latest code on main.
Please do not report security vulnerabilities in public issues.
- Share details privately with project maintainers.
- Include reproduction steps, impact, and affected area.
- If possible, include a minimal proof of concept.
Response target:
- Initial acknowledgement within 72 hours
- Triage and next steps as soon as validated
- Never commit API keys, service account files, tokens, or secrets.
- Use environment variables or local, ignored files for credentials.