Do not open a public issue for a suspected vulnerability that could expose private infrastructure, credentials, customer or personal data, or an actively deployed product or service.
Use GitHub's private vulnerability reporting feature when enabled for the affected repository. Include the affected component, reproduction conditions, expected impact, and a safe way to validate the report. Do not include live secrets or test against systems, accounts, or infrastructure without explicit authorization.
Each repository defines its own supported versions. When no version policy is published, reports concerning the current default branch or latest release will be reviewed on a best-effort basis. Reports for private repositories must use the authorized reporting channel available to repository collaborators.