Reporting a vulnerability
1
Choose a private channel
- GitHub (preferred): open a private report from the repository’s Security tab using “Report a vulnerability” (direct link).
- Email:
[email protected]
2
Include the details
A description and impact, steps to reproduce (a proof of concept helps), affected versions/components, and any suggested fix.
3
We track it privately
Every report is tracked in a private GitHub Security Advisory. If you email us, we open the advisory on your behalf.
What to expect
We score issues with CVSS 3.1 and prioritise remediation by severity:
These are best-effort targets measured from when we validate and accept a report, not guarantees. We follow coordinated disclosure with a default 90-day window, and publish a GitHub Security Advisory (requesting a CVE where applicable) once a fix ships.

