This policy covers every ReactiveUI repository that does not carry its own SECURITY.md. Each
repository supports only its latest released packages, or the current state of its default branch
where it ships no packages. Upgrade before reporting an issue.
Report vulnerabilities through GitHub private vulnerability reporting, on the Security tab of the repository the vulnerability affects. Where the affected repository is not clear, use this repository:
Do not open a public issue, pull request, or discussion for a security report.
Include the affected repository, the package version or commit you tested, steps to reproduce, and the impact you believe it has. A minimal reproduction is the most useful thing you can attach.
You will get an acknowledgement on the advisory thread, and updates there as the report is triaged and fixed. Once a fix is released the advisory is published with credit to the reporter unless you ask otherwise.