Please report security issues privately, not in a public issue.
Use GitHub's private vulnerability reporting on the affected repository: open its Security tab and choose Report a vulnerability. That gives you a private thread with the maintainers.
We use this rather than a security email address because this organization publishes no
personal contact details. If the affected repo does not have private reporting enabled,
report it on meta instead
and say which repo it affects.
This is a volunteer-run community organization, not a company with an on-call rota. We aim to acknowledge a report within a week. If a week passes with no reply, please ping #jolt on the Clojurians Slack without describing the issue publicly.
Each project here has its own maintainers and its own risk profile. A report is handled by that project's maintainers, with org admins available to help.