Report suspected vulnerabilities privately to research@gemacode.org.
Include the affected repository and version, reproduction steps, practical impact and any proposed mitigation. Do not open a public issue containing an unfixed vulnerability, secret, personal record or private evidence.
The maintainers will acknowledge a complete report, reproduce it when possible, coordinate a correction and publish an advisory when disclosure is safe.