We take security bugs seriously and appreciate your efforts to responsibly disclose your findings. To report a security issue, please use the GitHub Security Advisory tab. We will send a response indicating the next steps in handling your report. After the initial reply to your report, we will keep you informed of the progress towards a fix and full announcement, and may ask for additional information or guidance.
Report security bugs in third-party modules or libraries to the person or team maintaining the module.