Please report security vulnerabilities privately using GitHub's private vulnerability reporting for this repository (Security tab → "Report a vulnerability"), rather than opening a public issue.
Include, where possible:
- A description of the vulnerability and its potential impact.
- Steps to reproduce it.
- The affected version/commit.
This project has a single maintainer and no formal SLA, but reports are taken seriously and acknowledged as soon as reasonably possible.
There are no numbered releases — the deployed application always tracks the main branch (see
docs/deployment.md). Security fixes are made against main only.