If you discover a security vulnerability in this project, please report it responsibly.
Please do NOT open a public GitHub issue for security vulnerabilities.
Instead, please report them via GitHub's private vulnerability reporting feature:
- Go to the Security tab of this repository.
- Click "Report a vulnerability".
- Fill in the details of the vulnerability.
Alternatively, you can email the GitHub Security Lab team at securitylab@github.com.
When reporting a vulnerability, please include:
- A description of the vulnerability and its potential impact.
- Steps to reproduce the issue.
- Any proof-of-concept code or output.
- Your suggested fix (if any).
We will acknowledge receipt of your report within 5 business days and aim to provide a resolution or mitigation plan within 30 days.
This policy applies to the code in this repository. For vulnerabilities in dependencies, please report them to the respective upstream projects.