We take security seriously across this project.
If you find a security issue, report it privately.
Include as much of the following as you can:
- The type of issue (for example, buffer overflow or cross-site scripting)
- The files involved
- The affected tag, branch, commit, or URL
- Any configuration needed to reproduce the issue
- Step-by-step reproduction instructions
- Proof-of-concept code, if available
- Potential impact and how someone could exploit the issue
We use this information to triage and respond quickly.