Please report security vulnerabilities through GitHub private vulnerability reporting:
- Go to the Security tab
- Click Report a vulnerability
- Fill out the form
We respond within 48 hours.
- Dependabot for dependency updates
- CodeQL for code scanning
- Secret scanning and push protection
