Repository-specific security policies and supported-version statements take precedence over this organization default.
Do not open a public issue, discussion, or pull request for a suspected vulnerability.
Use the affected repository's Security tab and select Report a vulnerability when private vulnerability reporting is available. Include the affected versions, impact, and the smallest safe reproduction you can share privately.
If no private reporting form is available, email
contact@shakacode.com with the subject
Security report: OWNER/REPOSITORY. In the first message, include only the
repository, affected version range, and a brief impact description. Wait for a
private channel before sending exploit details, credentials, customer data, or
proof-of-concept payloads.
We aim to acknowledge reports within five business days. Please allow maintainers reasonable time to investigate and coordinate a fix before public disclosure.
Unless the affected repository documents a different window, maintainers focus security fixes on the latest stable release. Reports against older versions are still welcome; remediation may require upgrading.