Do not open a public issue containing vulnerability details, credentials, exploit code, private data, or affected-user information.
Use the affected repository's Security tab and select Report a vulnerability to open a private report. Follow any repository-specific instructions shown there.
If private vulnerability reporting is unavailable, open a public issue containing only:
- a request for private contact;
- the affected repository name;
- a safe way to reach you.
Do not include the vulnerability itself in that issue.
A useful private report includes the affected revision or release, reproduction steps or a proof of concept where safe, expected and observed behavior, impact, and any suggested mitigation.
Each repository defines its supported versions and security boundary. Pre-release projects may support only the latest revision.
Reports are reviewed in good faith. Greyfoundry may ask for additional information, coordinate a fix and disclosure timeline, or close reports that are out of scope or cannot be reproduced. Please avoid public disclosure until a coordinated resolution is available.