Tell us privately. Do not open a public issue, discussion, or PR for security stuff.
Open a GitHub Security Advisory on the DATA-AI repo, or email the maintainers directly. The link lives in the repo's security tab.
When you write it up, include as much as you safely can:
- What's broken, in plain language
- How to reproduce it (redact credentials and customer data, please)
- Which component / version / config is affected
- What an attacker could realistically do with it
- A fix or mitigation, if you have one
We'll get back to you, confirm what we've seen, and coordinate a fix and disclosure timeline on the same channel.
Please keep it off Twitter, off Hacker News, off Weibo, off the company all-hands. We know it's tempting, but premature disclosure makes the window for everyone worse.
We'll cut a release and credit you in the advisory (unless you'd rather stay anonymous). That's it.