For the org-wide security policy and reporting flow, see:
https://github.com/jarvis-atelier/.github/blob/main/SECURITY.md
If you found a vulnerability in this specific repo, do not open a public issue. Follow the private reporting process described in the org policy.