Please report security issues privately, using GitHub's private vulnerability reporting on this repository: open the Security tab and choose Report a vulnerability. That opens a channel visible only to the maintainer.
Please do not open a public issue for a security problem, and please do not post details publicly before they have been addressed.
No email address is published for this. Clause 10.5 of the licence states that contact should be made through the hosting platform account, and private vulnerability reporting is that channel.
These are personal projects published for evaluation, not operated services. There is no production deployment, no user data, and no infrastructure behind this repository. Reports about the code itself are welcome; there is no bug bounty and no service-level commitment.
Reports are read, but this is a personal account and not a staffed security team, so no response time is guaranteed.
The licence permits you to run the work locally to evaluate or verify it. It is provided as-is, with no warranty, and should not be relied on for any safety-critical, financial, medical or legal decision. See sections 7 and 8 of the LICENSE.