Security
Use the disclosure channel.
Follow the current instructions at sovn.run/security and the published security.txt.
Do not include credentials, private keys, exploit payloads containing customer data, or unrelated personal information in the initial report.