Do not open a public issue with vulnerability details, credentials, personal data, private hostnames, or private logs.
Use the affected repository's Security tab and select Report a vulnerability when that option is available. This creates a private report for the repository maintainers.
If private vulnerability reporting is unavailable, open a minimal public issue that asks a maintainer to establish a private channel. Include no exploit steps, secret values, or sensitive evidence in that issue.
This policy covers repositories in the seankoji-com organization. Report the
affected repository and version, the impact, and the smallest safe reproduction
you can provide privately.
Maintainers will acknowledge valid reports, assess impact, coordinate a fix, and publish an advisory when public disclosure is appropriate. Do not test against systems or data you do not own or have permission to access.