# Security policy Please do not open a public issue for a suspected vulnerability or include credentials, tokens, database files, logs, or private DNS data in a report. Use the repository's **Security** tab and select **Report a vulnerability** to send the maintainers a private report. Include the affected version, impact, reproduction steps, and a minimal proof of concept with all sensitive values removed.