The team takes security bugs in its products seriously. We appreciate your efforts to responsibly disclose your findings, and will make every effort to acknowledge your contributions.
To report a security issue, please use the GitHub Security Advisory "Report a Vulnerability" tab.
The team will send a response indicating the next steps in handling your report. After the initial reply to your report, the security team will keep you informed of the progress towards a fix and full announcement, and may ask for additional information or guidance.
Please report security bugs in third-party modules to the person or team maintaining the module.
In order to quickly deal with issued vulnerabilites, your disclosure may at least embed:
- Concerned versions
- Quick description
- Proof of Concept according to our vulnerability disclosure program