Skip to main content
Do not disclose suspected vulnerabilities in public issues, discussions, or pull requests. Email GiacoLenzo2109@proton.me and include:
  • the affected component and version or commit;
  • the conditions required to reproduce the issue;
  • a minimal proof of concept using non-sensitive test data;
  • the expected security impact;
  • any suggested mitigation.
Do not include real credentials, captured data, production targets, tracking identifiers, browser profiles, or personal information.
Security fixes are applied to the latest version on the default branch. Issues limited to the intended privileges and current session of an already authorized administrator, self-XSS, and cosmetic defects without security impact are normally out of scope. The repository security policy is the canonical source for current scope and submission requirements.
Last modified on August 28, 2026