Security fixes are developed on the latest state of the default branch.
Please do not open a public GitHub issue for security problems.
Instead, contact the maintainer privately through GitHub and include:
- a clear description of the issue;
- reproduction steps or a proof of concept;
- impact assessment;
- any suggested remediation if you have one.
If GitHub private vulnerability reporting is enabled for the repository, prefer that channel.
We will acknowledge reports as quickly as possible, investigate them, and work toward a fix before public disclosure.