Report security vulnerabilities privately through GitHub Security Advisories on the affected repository:
Repository → Security → Report a vulnerability
If the affected repository is not obvious, open the advisory on any repository in this organization and it will be routed.
Please do not report vulnerabilities through public issues, pull requests, or discussions — those are visible to everyone before a fix exists.
This policy covers the repositories in the tsvsheet organization and the domains they operate.