Use the private security-advisory flow on the affected public repository. Do not disclose a suspected vulnerability in a public issue.
Reports should include the repository and commit, reproduction steps, impact,
and any proposed mitigation. Repository-specific SECURITY.md files define
their exact scope and supported versions.
The public repositories contain reference implementations. Issues involving a private integration, signer, executor, production budget store, data source, or approval service must be reported through the relevant private channel.