Preferred: use GitHub's private vulnerability reporting — Security tab → Report a vulnerability on this repo. This keeps the report private until a fix is out.
Do not open a public issue for a security concern. If private reporting isn't available, open a minimal public issue asking for a private channel — without any detail about the flaw.
In scope: this repo's own code.
Out of scope:
- Vendored third-party bundles (if any) — report upstream to the original project instead.
- Any external API or infrastructure this project talks to — report to that provider directly.
This is maintained solo, best-effort, no SLA — but security reports get priority over everything else in the backlog.