Use this repository's GitHub Security tab and choose Report a vulnerability to open a private vulnerability report. Do not include vulnerability details, credentials or exploit material in a public issue or pull request.
If private vulnerability reporting is not available, do not publish the details. Contact a repository owner through their verified GitHub profile and ask them to enable a private reporting channel. Public repository readiness remains blocked until that route is enabled and verified.
Include affected versions, impact, reproduction steps and a redacted description of any exposed material. Maintainers should acknowledge the report privately, preserve evidence, rotate confirmed credentials through their owner and coordinate disclosure.
Security fixes target the latest commit on main and the most recent official app
release. Older builds may be asked to upgrade when a fix depends on native changes.