Do not open a public issue for an unpatched vulnerability. Use the target
repository's private vulnerability reporting feature when available. If it is
not available, email danil@nddev.it.com with the repository, affected
versions, impact, reproduction details, and known mitigations.
Do not include credentials, personal data, or live exploit material beyond what is necessary to reproduce the issue. We will acknowledge a complete report as soon as practical, coordinate remediation, and credit reporters who want attribution.
Only maintained releases and the default branch are supported unless a repository documents a broader support window.