If you believe you have found a security issue in a rstream repository, please avoid opening a public issue with exploit details.
Use GitHub private vulnerability reporting for the affected repository when it is available. If that path is not enabled yet, contact the maintainers privately at reports@rstream.io before disclosing the issue in public.
When reporting an issue, include:
- the affected repository, package, command, or API surface
- the version or commit you tested
- the impact you observed
- enough reproduction detail for the issue to be validated
Security reports are treated as a priority and handled through a coordinated fix and disclosure process.