Do not open a public issue for security vulnerabilities.
Please report security issues privately using GitHub's security advisory feature.
If that link does not open a form, write to the maintainers privately instead — TODO(/onboard): private security contact.
If that line still shows a TODO placeholder, this project has no private channel configured. Ask the account or organization that owns this repository for one before sending anything.
Do not post the details publicly — issue, discussion, or pull request — and do not send them to addresses from this repository's commit history: in a fork those belong to the template's authors, not this project's maintainers, and GitHub noreply addresses accept no mail.
Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
TODO(/onboard): which versions receive security fixes. Until that is set, report against the latest release — an unset field here is not a closed door.
TODO(/onboard): how long a reporter waits for a first reply, and how long for a fix. Until those are set, this project states no target — report anyway, and ask for a status update if you have not heard back.