The version published from the repository's current default branch is supported. Older snapshots and forks may not receive security fixes.
Do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability report and include:
- the affected route, file, workflow, or dependency;
- steps to reproduce;
- likely impact;
- the environment used for testing; and
- a suggested mitigation, if available.
Please avoid accessing data that is not yours, degrading the public site, testing third-party official sources beyond ordinary browsing, or publishing details before a fix is available. This project does not offer a bug bounty.
The maintainer aims to acknowledge a complete report within seven days, confirm whether it is in scope, and coordinate disclosure after a fix. Timelines depend on severity and maintainer availability.
- build or deployment behavior that could expose repository-only material;
- script injection, unsafe URL handling, or compromised static assets;
- dependency or GitHub Actions supply-chain risks;
- workflow permissions and Pages artifact integrity; and
- a privacy claim that is contradicted by the shipped site.
Data corrections, stale sources, legal-status questions, accessibility defects, and ordinary interface bugs are important but are not security vulnerabilities. Use the repository's structured public feedback forms for those reports, and do not include sensitive information.