Do not open a public issue for a vulnerability that could put visitors or contributors at risk. Report it privately to the repository owner through GitHub. Do not include credentials, private member data or confidential event information in reports or contributions.