Do not open a public issue for a suspected vulnerability.
Report it privately with GitHub Private Vulnerability Reporting: Report a vulnerability privately.
Please include:
- the affected files or workflow;
- the impact;
- the smallest useful reproduction.
The maintainer will acknowledge the report and coordinate disclosure and remediation through the private advisory.
The latest released version receives security fixes. The main branch may
already contain fixes intended for the next release.