Please do not report security vulnerabilities via public GitHub issues.
Instead, use GitHub's private security advisory feature to report the issue confidentially.
Include:
- A description of the vulnerability
- Steps to reproduce
- Potential impact
You'll receive a response as soon as possible. For a solo-maintained project, expect a reply within a few days.