This repository has not made a public stable release. Security fixes target the default branch.
Do not open a public issue for a vulnerability that could expose credentials, execute untrusted code, alter published checksums, or compromise the GitHub Pages deployment. Use GitHub private vulnerability reporting when it is enabled. If it is unavailable, contact the repository owner through the private contact method on their GitHub profile and include the affected commit, reproduction steps, impact, and any proposed mitigation.
Never submit secrets, restricted data, household-level sensitive records, producer-identifiable financial data, or credentials. Public outputs must be aggregate and redistribution-compatible. The public site has no runtime secrets or privileged backend.
Maintainers will acknowledge a complete report within seven days, publish a remediation plan when impact is confirmed, and credit reporters who request credit. Do not disclose before a fix or coordinated disclosure date.