Security fixes are developed against the main branch. Before reporting a
vulnerability, verify that it is reproducible on main or the latest relevant
supported release.
Do not report security vulnerabilities through public GitHub issues, discussions, pull requests, or other public channels.
Use GitHub's private vulnerability reporting for this repository. Alternatively, email vulnerability reports to elizabeth.jennifer.myers+fcpw-security@gmail.com. Do not include sensitive vulnerability details in a public message.
Include enough information to reproduce and assess the vulnerability:
- The affected version and the commit against which it was reproduced;
- A clear description of the vulnerability and its potential impact;
- A minimal reproducer or proof of concept;
- Relevant environment and configuration details;
- Any known mitigations or workarounds; and
- Whether automated tools assisted in discovering or preparing the report.
If an automated tool discovered the vulnerability, independently verify the
result against main or the latest relevant supported release before
reporting it. Reports and follow-up communications must be meaningfully
reviewed and deliberately submitted by a human in accordance with
CONTRIBUTING.md.
Please allow the maintainers a reasonable opportunity to investigate and address the vulnerability before public disclosure. Do not share sensitive details publicly until the maintainers confirm that disclosure is appropriate.