Report a vulnerability privately through GitHub's Report a vulnerability button on this repository's Security tab. That opens a private advisory only the maintainers can read.
Do not open a public issue for a vulnerability, and do not send details to a mailing list or a chat channel.
| Acknowledgement | within 3 working days |
| First assessment | within 10 working days |
| Fix or a stated reason there will not be one | within 90 days |
If we miss one of those, say so publicly. A disclosure window nobody is held to is worse than none, because it asks a reporter to wait on a promise that was never load-bearing.
This repository's code and the documents it publishes. A vulnerability in a dependency belongs to that dependency; tell us anyway if it reaches users through us.
A specification that permits something you consider unwise is a specification disagreement — open an issue, because that is a conversation worth having in public. A published file proving less than a reader assumes is the stated design: publishing a file at a domain proves that somebody can write to that host, and it never proves an organisation is who it says it is.