Report security problems privately, not in a public issue. On GitHub, open the repository's Security tab and choose Report a vulnerability. Only the maintainers can see the report.
If the repository has no Report a vulnerability button, email info@automatethe.cloud with "Security" in the subject line instead.
Include what you found, how to reproduce it, and what an attacker could do with it.
Anything that makes infrastructure built with our code more exposed than its inputs and documentation say it should be: for example, a default that allows traffic in, a permission or rule broader than documented, or a validation that lets an insecure value through.
Fixes are made to the latest release.