We take security bugs seriously. We appreciate your efforts to responsibly disclose your findings and will make every effort to acknowledge your contributions.
Please do not report suspected vulnerabilities in public issues, discussions, pull requests, or other public channels.
Instead please create a Security Advisory.