Report security vulnerabilities through GitHub private vulnerability reporting. Include the affected version, impact, and a minimal redacted reproduction. Do not disclose an unpatched vulnerability in a public issue.
Never attach raw runtime evidence to an issue, pull request, or commit. This
includes Power.log, .hdtreplay, .hsreplay, HearthRanger or Hearthstone
logs, HDT runtime XML exports, private runtime evidence folders, deck codes,
and unredacted local output packages. Share only the smallest sanitized
extract needed for diagnosis through the private reporting channel.
In particular, raw logs, replays, all deck codes, runtime XML, and unredacted packages must not be filed publicly.