We have enabled the ability to privately report security issues through the Security tab above.
Here are the details on how to file a private vulnerability report.
A repository owner/maintainer will respond as fast as possible to coordinate confirmation of issue and remediation, though please allow up to 14 days.
Thank you for helping to ensure this code stays secure.