To report a security issue, please use the GitHub Security Advisory "Report a Vulnerability" tab. Please do not report security issues as public issues or pull requests.
We will send a response indicating the next steps in handling your report. After the initial reply to your report, the maintainers will keep you informed of the progress towards a fix and full announcement, and may ask for additional information or guidance.
Report security bugs in third-party dependencies to the person or team maintaining the dependency.