Do not open a public issue for a security vulnerability.
Report it privately in the affected repository: Security → Report a vulnerability (GitHub private vulnerability reporting). If that is not available, write to hola@diluxone.com with "Security" in the subject.
Include what is affected, how to reproduce it, and the impact you see. We acknowledge within 72 hours, triage within 7 days, and agree on a disclosure date with you. Fixes go to the latest release; reporters are credited unless they prefer not to be.
Repositories may add their own SECURITY.md with product-specific details.