Please do not open a public issue for security vulnerabilities.
Report it privately through GitHub instead:
- Open the Security tab of the affected repository.
- Click Report a vulnerability to start a private security advisory.
This lets us discuss and fix the issue before any public disclosure. We aim to acknowledge reports within a few days.
Security fixes target the latest released version (or the default branch when there is no release). Older versions are generally not backported.
Once a fix is ready we publish the advisory and credit the reporter, unless anonymity is requested. Thank you for helping keep Atypical Consulting's projects safe.