Security Reporting¶
Do not disclose an exploitable vulnerability through a public Issue, Pull Request, or Discussion.
Use GitHub Private Vulnerability Reporting:
Report a vulnerability privately
A useful report includes the affected version, environment, impact, reproducible steps, and whether credentials, private data, or code execution are involved.
The canonical policy is SECURITY.md.
For the framework's technical security model, see Security.