Please do not open a public issue for a suspected vulnerability.
Use GitHub's private vulnerability reporting for this repository:
- Open the repository's Security tab.
- Choose Report a vulnerability.
- Include the affected package version, impact, reproduction steps, and any known mitigations.
If possible, include a minimal test case without real credentials, customer data, or production endpoints. Reports are reviewed privately, and public disclosure should wait until a fix or mitigation is available.
For ordinary bugs and feature requests, use the public issue tracker.
Security fixes are released for the latest published version. Upgrade to the latest release before reporting an issue that may already have been addressed.