Please do not open a public issue for a suspected vulnerability or exposed secret.
Use the affected repository's Security tab to submit a private vulnerability report when that option is available. Otherwise, contact the repository owner through the contact method listed on the GitHub profile and include only the minimum information needed to reproduce the issue.
Reports should identify the affected repository and revision, expected impact, reproduction steps and any suggested mitigation. Do not include real credentials, personal data or destructive proof of concept material.
Portfolio and learning repositories support only the latest revision of their default branch. Archived repositories are unsupported and are marked as such on GitHub.