Do not disclose suspected vulnerabilities in a public issue, discussion, pull request, or chat channel.
Use the affected repository's private vulnerability reporting feature when it is available. Otherwise, contact an organization owner through the established private company channel and include:
- the affected repository and version or commit;
- steps to reproduce the issue;
- the possible impact;
- any suggested mitigation;
- a safe way to contact you for follow-up.
The organization will acknowledge the report, assess severity, coordinate remediation, and agree on disclosure timing with the reporter when appropriate.
Each product repository documents its supported production version. Security fixes are applied to actively supported versions according to the product's release policy.