- Do not open public issues for security-sensitive reports.
- Contact the repository owner via GitHub private messaging or email.
- Expect acknowledgment within 7 days and a resolution plan within 30 days.
Security reports should focus on issues that could lead to:
- Unintended disclosure of private data (e.g., API keys in committed files)
- Credential leakage in pipeline tooling
- Supply chain risks in dependencies