Report a suspected vulnerability privately through GitHub's private vulnerability reporting on the affected repository. Open the repository's "Security" tab and select "Report a vulnerability".
Do not open a public issue for a suspected vulnerability.
Include:
- The affected repository, version, or commit.
- Steps to reproduce the issue.
- The impact you assess.
A maintainer will acknowledge your report on a best-effort basis and follow up with next steps. This project makes no service-level or response-time guarantee.
This policy covers the code in Major Context repositories. It does not cover a third-party service a project integrates with; report a vulnerability in a third-party service to that service's own maintainer.