Please report suspected security vulnerabilities privately through GitHub's repository security reporting mechanism rather than publishing exploit details in a public issue.
Do not include credentials, access tokens, personal data or other secrets in public reports.
Security findings should be triaged, reproduced where possible, fixed or mitigated, and documented with the affected component and supported version. Exposed credentials must be revoked/rotated rather than merely deleted from the current source tree.
This policy covers source code, dependencies, CI/CD workflows, configuration and repository-integrated tooling.