Please report vulnerabilities privately through the affected repository's Security → Report a vulnerability flow. Include:
- the affected package and version;
- a minimal reproduction or proof of concept;
- the expected impact;
- any known mitigations.
Do not open a public issue, discussion, or pull request for an undisclosed vulnerability.
The latest published minor line of each package receives security fixes. Older 0.x lines may be asked to upgrade because public APIs are still stabilizing. Package-specific policies override this organization default.
We will coordinate disclosure after a fix or mitigation is available and credit reporters who want to be named.