If you believe you have found a security vulnerability in a project maintained by Webinertia, please do not open a public issue. Instead, report it privately using GitHub's private vulnerability reporting:
- Go to the affected repository on GitHub.
- Open the Security tab.
- Click Report a vulnerability (under "Advisories").
- Fill out the advisory form with as much detail as you can, including:
- The affected package/repository and version(s)
- Steps to reproduce the issue
- A summary of the vulnerability and its potential impact
- A suggested fix or mitigation, if you have one
- We will investigate and work with you to confirm the vulnerability.
- We will not disclose the issue publicly, and ask that you do the same, until a fix has been released.
- We will patch the current release branch, as well as the immediate prior minor release branch.
- We will issue new patch releases for each affected branch as soon as a fix is ready.
- We will publish a GitHub Security Advisory (GHSA) on the affected repository detailing the vulnerability, affected versions, and remediation steps, crediting the reporter unless anonymity is requested.