DO NOT PUBLISH SECURITY REPORTS PUBLICLY.
If you discover a security vulnerability within PHP CS Fixer, please disclose it via https://github.com/PHP-CS-Fixer/PHP-CS-Fixer/security/advisories.
Report security bugs in third-party libraries directly to the group maintaining that library.