Use GitHub's private vulnerability reporting option when it is available for the affected repository. Do not open a public issue containing an exploit, live credential, sensitive file content, customer or banking data, private repository details, or personal data.
If private vulnerability reporting is not available, open a minimal public issue that requests a private reporting channel without disclosing sensitive details. Include only the affected public repository and version.
A useful private report includes:
- the affected version or commit
- a minimal reproduction using synthetic data
- expected and observed behavior
- likely impact and any known mitigations
Security fixes and disclosure timing depend on severity, reproducibility, and the maintenance status of the affected project. No repository should be treated as a substitute for professional security review.