Use GitHub private vulnerability reporting.
If private reporting is unavailable, open a public issue asking for a private contact path. Do not post exploit details, credentials, kubeconfig contents, tokens, certificates, or cluster-specific sensitive data publicly.
Include affected version or commit, operating system, impact, and minimal reproduction steps. State whether credentials or Kubernetes resources may be exposed or modified.
Security fixes target latest release and main. Older releases and local source builds are unsupported.
Reports are triaged privately. Public details wait for a fix or mitigation.
Read safety, data handling, and architecture for product safety guidance.