If you thank you have discovered a potential vulnerability, please report it using GitHub’s built-in Security Advisories feature. This ensures the report remains private until it is reviewed by maintainers and an appropriate fix is in place.
- Go to this repository’s "Security" tab.
- Select "Report a vulnerability".
- Provide as much detail as possible so we can investigate and address the issue promptly.
Please do not disclose any details of the issue publicly until we have had a chance to investigate and provide a fix. This helps keep the project and its users safe.
Please only submit reports via this method if you are absolutely sure you have found a true security vulnerability.
A true vulnerability is a flaw that an attacker can use to harm the system, such as:
- Remote Code Execution (RCE)
- Unauthorized access to private data
- Exposed credentials (API keys, passwords, etc.)
The following issues are NOT considered true vulnerabilities and will be closed:
- Standard bugs, crashes, or software errors
- Missing features or feature requests
- Issues caused by how you set up or configured the software
Non-security bugs should be filed using the regular issue tracker.