Security fixes are provided for the latest code on the main branch and the current production deployment. Older versions and forks may not receive updates.
Please report suspected vulnerabilities privately to t a b k r a m [at] g m a i l [dot] c o m. Do not open a public issue, discussion, or pull request for a security report.
Include, when possible:
- A clear description of the issue and its potential impact
- Steps to reproduce it or a minimal proof of concept
- The affected URL, commit, or version
- Any suggested remediation or mitigation
We aim to acknowledge reports within 4 business days and will keep you informed about triage and remediation. Please give us reasonable time to investigate and release a fix before disclosing the issue publicly.
The project is a client-side web application. Reports involving its source code, the deployed application, dependency vulnerabilities with a demonstrated impact, or the GitHub Pages deployment are in scope. Please do not send sensitive data beyond what is necessary to reproduce the issue.