Active support is paused indefinitely, so response and remediation times are not guaranteed.
Do not open a public issue containing credentials, OAuth tokens, API keys, cookies, session data, private server details, or immediately exploitable secret material. If GitHub private security reporting is enabled for this repository, use Security → Report a vulnerability. Otherwise, publish only a redacted issue that is safe for public viewing and ask the repository owner how to provide sensitive details.
If a credential has already been exposed, revoke or rotate it immediately. Removing it from the latest commit is not sufficient if it remains in Git history.