Do not disclose security vulnerabilities through public issues.
Use GitHub private vulnerability reporting when available. Otherwise, contact the repository owner privately through the verified contact information on the Metalymph GitHub profile.
Include reproduction steps, affected revisions, expected impact, and known mitigations.