Please do not open a public issue for a security problem. A public report tells everyone about the weakness at the same moment it tells us.
Report it privately through GitHub instead: open the Security tab on the affected repository and choose Report a vulnerability. This creates a private advisory that only the maintainers can see. If the affected repository is private and you cannot reach that tab, open an issue asking for a private channel — without describing the problem — and we will follow up.
Please include what you can:
- what the problem is, and what an attacker could do with it
- the steps or conditions needed to reproduce it
- the affected repository, and the version, branch or commit if you know it
We are a small volunteer team, so we cannot promise a response time. We will acknowledge your report, tell you whether we consider it in scope, and let you know when a fix ships. We are grateful for reports made in good faith and will not pursue anyone who reports honestly and gives us a reasonable chance to fix the problem before going public.
Some of our repositories process personal data belonging to members of our church. Problems that expose that data are the ones we most want to hear about, whatever their technical severity looks like in isolation.