Security fixes target the latest main branch. Report suspected vulnerabilities privately to security@gapwise.ca or through GitHub private vulnerability reporting for this repository when available. The public policy is at gapwise.ca/security.
Include reproduction steps using test data and the expected impact. Do not put credentials, private timetables, tokens, or exploit details in a public issue. Do not access another person's data or disrupt production services while testing.