We encourage responsible disclosure practices for security vulnerabilities.
If you believe you've found a security-related bug, fill out a new vulnerability report via GitHub directly. To do so, follow these instructions:
- Click on the
Securitytab in the project repository. - Click the green
Report a vulnerabilitybutton at the top right corner. - Fill in the form as accurately as you can, including as many details as possible.
- Click the green
Submit reportbutton at the bottom.
A Tidelift Subscriber?
If you prefer to, you may also report a security vulnerability through the Tidelift security contact. Tidelift will coordinate the fix and disclosure. This is not the maintainers' first preference, though. Please, use the GitHub's vulnerability reporting option, whenever possible.