Do not disclose vulnerabilities in public issues, discussions, or pull requests.
Use GitHub's private vulnerability reporting for this repository. If private reporting is unavailable, contact the maintainer through their GitHub profile and request a private channel without including vulnerability details in the first message.
Include affected versions, impact, reproduction steps, and any known mitigation. You should receive an acknowledgement within seven days; timelines for a fix and coordinated disclosure depend on severity and scope.
Security fixes target the latest commit on main. Applications created from this template must maintain their own dependency updates and security policy.