Do not report credentials, private customer data, or exploitable vulnerability details in a public Issue.
For repositories with private vulnerability reporting enabled, use Security → Advisories → Report a vulnerability. Otherwise, contact a moyuan-labs organization owner privately before sharing sensitive details.
Include the affected repository and revision, impact, reproduction prerequisites, and a minimal proof of concept with secrets removed. Maintainers will acknowledge the report, validate scope, and coordinate remediation and disclosure.
Repository-specific security instructions override this default when present.