Do not report suspected vulnerabilities in a public issue.
Use the affected repository's Security tab and select Report a vulnerability to open a private security advisory. Include:
- the affected repository, version, and hardware;
- clear reproduction steps;
- expected and observed behavior;
- potential motion, configuration, Bluetooth, USB, or supply-chain impact; and
- any suggested mitigation.
Avoid testing on powered machinery. Reproduce with motion physically disabled and do not include credentials, private keys, Bluetooth addresses, or receiver serial numbers unless the private report requires them.
Only the latest supported release and current default branch receive security fixes unless a repository states otherwise.