Problem
The repository has no SECURITY.md and no documented private channel for reporting a vulnerability. For a package with thousands of forks, a JOSS publication, and wide use in teaching environments, a finder's only options today are a public issue (which discloses the problem before a fix exists) or an untracked email (no SLA, no audit trail).
GitHub Private Vulnerability Reporting is a one-click enablement in repository settings and gives reporters a private, tracked channel with a coordinated-disclosure workflow.
Acceptance criteria
From the July 2026 technical-debt audit (AI-assisted; claims verified against 28d4b3b on 2026-07-25).
Problem
The repository has no
SECURITY.mdand no documented private channel for reporting a vulnerability. For a package with thousands of forks, a JOSS publication, and wide use in teaching environments, a finder's only options today are a public issue (which discloses the problem before a fix exists) or an untracked email (no SLA, no audit trail).GitHub Private Vulnerability Reporting is a one-click enablement in repository settings and gives reporters a private, tracked channel with a coordinated-disclosure workflow.
Acceptance criteria
SECURITY.mdat the repository root: supported versions, how to report, expected response timeSECURITY.mdpoints at the private reporting channel rather than an email addressFrom the July 2026 technical-debt audit (AI-assisted; claims verified against
28d4b3bon 2026-07-25).