# Security
Report vulnerabilities privately through GitHub Security Advisories:
https://github.com/canact/canact/security/advisories/new
Do not open a public issue for a security report.
We aim to acknowledge a report within 7 days. Include enough detail
to reproduce the issue (version or commit, steps, and impact).