Do not post vulnerability details in public issues, discussions, pull requests, or other public channels.
For the affected repository, use GitHub private vulnerability reporting when it is available: open the repository's Security tab, choose Advisories, then Report a vulnerability. Include the affected component or version, impact, reproduction steps, and any suggested mitigation.
If private vulnerability reporting is unavailable, open a public issue containing no sensitive details and ask the maintainers to provide a private contact channel. Wait for that channel before sharing technical details.
Moonweave Systems is small and owner-maintained. Reports will be reviewed on a best-effort basis; acknowledgement and remediation timelines cannot be guaranteed. Security support generally focuses on current releases and the default branch of actively maintained repositories.