Please do not publish credentials, customer information or exploitable security details in a public issue or pull request.
Use the repository's Security → Advisories → Report a vulnerability option when private vulnerability reporting is enabled. If the option is unavailable, open an issue containing only a request for a private reporting channel, without the sensitive details. A maintainer can arrange the channel before you send details.
For accidentally exposed credentials, revoke or rotate them promptly through the appropriate administrator. Removing a file in a later commit does not remove it from existing history, downloads or forks.
Community maintainers offer no guaranteed response time or security update period. All versions can be reported; there is no promise of maintained product support.