Please report undisclosed security vulnerabilities privately using GitHub Private Vulnerability Reporting. Do not open a public issue for a vulnerability that has not yet been disclosed.
We aim to acknowledge reports within 72 hours.
For bugs and issues that are not security-sensitive, or for vulnerabilities that are already publicly disclosed (e.g. published CVEs in dependencies), use GitHub issues.