- DO NOT POST ABOUT IT PUBLICLY
- Send an email to bkeepers@github.com with details about the security vulnerability.
- After a fix has been released, a public announcement will be made giving all glory and honor to you.
- Search the mailing list to see if anyone else had the same issue.
- Check the GitHub issue tracker to see if anyone else has reported issue.
- If you don't see anything, create an issue with information on how to reproduce the issue.
- Fork the project on GitHub.
- Make your changes with tests.
- Commit the changes without making changes to the Rakefile, Gemfile, gemspec, or any other files that aren't related to your enhancement or fix.
- Send a pull request.