Report security vulnerabilities privately through GitHub's private vulnerability reporting, which is enabled for this repository:
https://github.com/ANcpLua/qyl/security/advisories/new
That channel keeps the report visible only to the maintainers until an advisory is published. Please do not open a public issue or pull request for a security problem, and please do not disclose the details publicly before a fix is available.
A useful report includes the affected component, the qyl version or commit, and the steps needed to reproduce the issue.
qyl is maintained by a single maintainer, so reports are triaged as time allows rather than against a guaranteed response window.
Fixes land on main and ship in the next release. Only the most recent released
version receives security fixes; earlier 1.x releases are not patched in place.
Confirmed vulnerabilities are disclosed through a GitHub Security Advisory on this repository once a fixed version is published.