Use GitHub's private vulnerability report. Do not post credentials, exploit details or private user data in a public issue.
Describe the affected version or commit, the impact, and a minimal synthetic reproduction. Remove personal data from attachments. No response-time guarantee is offered. These repositories are educational examples, not production services.
If you accidentally publish a credential, revoke or rotate it at its provider; deleting the text alone does not invalidate it. Ordinary setup questions belong in the public Issues tab with a short, redacted example.