Do not open a public issue for a suspected vulnerability or exposed credential. Report it privately to the Global repository maintainers through GitHub Security Advisories.
Include the affected version, reproduction details, impact, and any suggested mitigation. Avoid including real family data, access tokens, or private keys in the report.
All secrets must be rotated immediately if they are ever committed, even when the commit is later removed from history.