If you find a security issue in this project, please report it privately:
- Use GitHub private vulnerability reporting: open the repository's Security tab and use "Report a vulnerability". This keeps the issue private until it is resolved.
- Do not open a public issue for security problems.
- A short description of the issue and its impact.
- Steps to reproduce (or a minimal proof of concept).
- Any suggested fix, if you have one.
- Acknowledgment within 5 business days.
- A fix or a detailed response within 30 days, depending on severity.
This site is a fully static export (no server, no database, no authentication). Most content lives in the browser, so the practical attack surface is limited to third-party assets and dependency supply chain. Report anything that concerns you — better safe than sorry.