Security fixes are normally made on the default branch and included in the next release. Older releases may not receive backports unless a repository states a different policy.
Do not open a public issue with vulnerability details.
- Open the affected repository's Security tab.
- Choose Advisories and then Report a vulnerability.
- Include the affected version or commit, impact, reproduction steps, and any suggested mitigation. Remove unrelated personal or confidential data.
If the private-report button is not available, open a public issue asking for a private security contact without including the vulnerability details. For a fork, first determine whether the issue belongs to the upstream project and follow the upstream project's security policy when it does.
Reports will be evaluated on a best-effort basis. Please allow time to confirm the issue and prepare a fix before publishing details. Credit is welcome but not required and will be coordinated with the reporter.