Please use the Issues section to report security bugs/vulnerabilities. Include the requested information listed below (as much as you can provide) to help us better understand the nature and scope of the possible issue:
- Type of issue
- Full paths of source file(s) related to the manifestation of the issue
- The location of the affected source code (tag/branch/commit or direct URL)
- Any special configuration required to reproduce the issue
- Step-by-step instructions to reproduce the issue
- Proof-of-concept or exploit code (if possible)
- Impact of the issue, including how an attacker might exploit the issue
We'll strive to acknowledge and send a more detailed response to your report ASAP. After the initial reply to your submission, the maintainers will endeavor to keep you informed of the progress being made towards a fix and full announcement, and may ask for additional information or guidance surrounding the reported issue.
If you have suggestions on how this process could be improved please submit a pull request or file an issue to discuss.