Do not report vulnerabilities with exploit details, credentials, or customer data in public issues.
Use Security → Report a vulnerability in the affected repository when available. If that option is unavailable, contact the project's documented maintainer privately to arrange a reporting channel before sharing sensitive details.
Include affected versions, a minimal reproduction, impact, and suggested mitigation. Redact secrets and personal data.
Maintainers should document supported releases in each project. Experimental projects do not imply production security guarantees or a response-time commitment.