Please do not report vulnerabilities, credentials, private data, or exploit details in a public issue, discussion, pull request, or chat transcript.
Use GitHub's private security advisory form for the affected repository when the repository exposes one. If it does not, use the canonical Base Foundry private advisory form at:
https://github.com/basefoundry/base/security/advisories/new
Include the affected repository and component, the earliest known version, a minimal reproduction, impact, and a safe contact method. A report does not need to include a weaponized proof of concept. Keep the report private until the maintainers agree on disclosure and remediation.
Repository-specific security policies may define a more appropriate private contact or threat model. They override this default for that repository but must preserve private reporting for security-sensitive material.
Support depends on the affected repository and release line. Include the exact version, commit, package revision, or workflow revision in every report so the maintainers can determine exposure and a remediation path.