Use GitHub Private Vulnerability Reporting for security reports:
- Open the repository's Security tab.
- Select Advisories.
- Select Report a vulnerability.
Include the affected component, reproduction steps, expected impact, and any suggested mitigation. Do not publish exploit details, credentials, personal data, or internal identifiers in a GitHub issue.
Useful reports include authentication or authorization bypasses, injection paths, unsafe handling of
uploaded content, accidental disclosure of sensitive information, and exploitable dependency issues.
The credential-free reference profile is intended for local evaluation and is not an
internet-facing deployment configuration.
Security fixes apply to the current default branch. Historical snapshots and modified copies are not supported.