Please do not report security vulnerabilities through public GitHub issues, discussions or pull requests.
Report them by e-mail to rgb.bugbounty@proton.me.
Please include as much of the following as you can:
- a description of the issue and its potential impact
- the affected repository and version (tag, branch or commit)
- steps to reproduce, and a proof of concept if available
We follow the principle of coordinated vulnerability disclosure: please give us a reasonable amount of time to address the issue before disclosing it publicly.