Please do not disclose suspected vulnerabilities in a public issue or discussion. Use the repository's Security tab to open a private vulnerability report. Include affected versions, reproduction steps, impact, and any suggested mitigation.
If private reporting is unavailable, contact the repository owner through their GitHub profile without including exploit details in the initial public message.
Security fixes are normally applied to the default branch and the latest supported release. Older versions may be unsupported unless a release line is explicitly documented as maintained.
You can expect acknowledgement after the report is reviewed. Timelines for remediation and coordinated disclosure depend on severity, exploitability, and release risk.