Security fixes are applied to the latest version on the default branch.
Use the affected repository's private vulnerability-reporting feature, under Security then Report a vulnerability. Do not open a public issue or pull request for a suspected vulnerability.
That feature is not available on every repository. Where the repository's
Security tab offers no Report a vulnerability button, email
ryan@duguid.com.au instead, with SECURITY in the
subject line. Email is unencrypted, so send only what the next paragraph
permits and wait for a private channel before sending anything more.
Most of the repositories without the feature are contribution forks of upstream projects. A vulnerability in the upstream code belongs to that project's own security policy, so report it there; use the address above only for something introduced by this account's changes.
Include a clear description, reproduction steps using fabricated data, likely impact, and any suggested mitigation. Never include client, taxpayer, employee, payroll, access-token or other sensitive data.
We will acknowledge a valid report within 7 days and coordinate the fix and disclosure timeline with the reporter.
If a repository has its own SECURITY.md, that repository-specific policy
takes precedence over this account-level default.