Do not open a public GitHub issue for a suspected vulnerability.
Use a private disclosure path instead:
- Open a GitHub security advisory for the repository if that feature is enabled.
- If advisories are not enabled yet, contact the maintainer privately using the contact information on the repository profile.
Include:
- affected component or file
- reproduction steps
- impact assessment
- any proof-of-concept or mitigation notes
- acknowledge receipt promptly
- validate the report
- prepare a fix and release plan
- coordinate public disclosure after a patch is available
Relevant reports include:
- dependency or supply-chain vulnerabilities
- unsafe command execution paths
- data corruption or integrity issues in pipeline stages
- dashboard or admin-surface issues that expose local execution or sensitive files