Report suspected bypasses privately through GitHub's Report a vulnerability feature. Never paste a live secret into an issue or test fixture.
False negatives for private-key material, invisible Unicode, or integrity drift are security-sensitive. Reports should include the smallest safe reproducer possible.