Report suspected vulnerabilities privately through GitHub's private vulnerability reporting.
This routes the report to the maintainer without public disclosure. Please include the affected route or component, reproduction steps, and the impact you observed. Expect an initial response within 7 days.
Do not open a public issue for security reports.
This is a continuously deployed site — only the currently deployed revision on
main is supported. Fixes ship forward; there are no backported releases.
In scope: the deployed web application and its serverless data API. Out of scope: third-party platforms the site links to, and findings that require physical access or a compromised maintainer device.