If you find a security issue in any duoaquila project, please report it privately rather than opening a public issue.
Use GitHub's private vulnerability reporting on the affected repo, or open a draft security advisory. I try to respond within a few days.