Please do not disclose vulnerabilities in a public issue or discussion. Use GitHub's private vulnerability reporting from the repository's Security tab.
Include the affected version or commit, operating system, reproduction steps, expected impact, and any suggested fix. Redact credentials, tokens, provider responses, local file paths, and personal usage data.
If private reporting is not available, open a public issue without technical details and ask the maintainers to enable a private reporting channel.
Security fixes target the latest published release and the current main branch. Older releases may not receive a
patch.