Email [email protected] with "SECURITY" in the subject. Do not open a public issue for anything involving secrets, personal data or a way to tamper with published results.
We aim to acknowledge a report within 5 business days and tell you our plan within 14 days. We do not run a bounty program.
A repository may have its own SECURITY.md with narrower scope. If it does, that one applies.