GitHub takes the security of our software products and services seriously, including the open source code repositories managed through our GitHub organizations, such as GitHub.
If you believe you have found a security vulnerability in this GitHub-owned open source repository, please report it first through GitHub's bug bounty program on HackerOne.
For other security-related concerns or questions, please use private GitHub Security Advisory reporting. See GitHub's private vulnerability reporting documentation for instructions.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Thanks for helping make GitHub safe for everyone.