Do not report suspected vulnerabilities in a public issue. Use GitHub private vulnerability
reporting in the repository that owns the affected package. If ownership is unclear, report it
privately to ml4t/ecosystem and identify the packages and versions that may be affected.
Include reproduction details, impact, affected versions, and any known mitigations. Do not publish exploit details until the maintainers complete coordinated disclosure.