Please do not disclose security vulnerabilities in a public issue or discussion.
Use GitHub's private vulnerability reporting feature in the affected public repository whenever it is available. Include:
- the affected repository, component, and version or commit;
- a clear reproduction or proof of concept;
- the likely impact;
- any suggested mitigation;
- whether the issue has been disclosed elsewhere.
We will acknowledge a complete report as soon as practical, investigate it, and coordinate disclosure after a fix or mitigation is available.
This policy covers public repositories owned by the Yila-AI GitHub organization. Third-party services and dependencies should also be reported to their respective maintainers when appropriate.