If you discover a vulnerability, please do not open a public issue with exploit details.
Open a private report when GitHub security advisories are enabled for the repository, or contact the repository owner directly.
For security-sensitive changes, pull requests should include:
- affected area
- risk summary
- verification performed
- any secret, auth, payment, Web3, or data migration considerations