# Security Policy ## Reporting a vulnerability Please report potential vulnerabilities privately through GitHub's **Security > Report a vulnerability** workflow rather than opening a public issue. Include reproduction steps, affected versions or commits, and the expected impact. Do not include device serials, personal file names, generated databases, or copied phone content in a report. A maintainer will acknowledge the report and coordinate validation and remediation through the private advisory.