Security and privacy fixes are applied to the latest released minor version.
Do not open a public issue containing credentials, student data, private paths, or a working exploit. Use GitHub private vulnerability reporting when it is available. Otherwise contact the repository owner privately through their GitHub profile.
Include the affected version, a minimal reproduction, impact, and suggested mitigation. Replace all real student or institutional data with synthetic placeholders.
Reports about unsafe path handling, accidental publication of local exam evidence, manifest traversal, release-integrity bypasses, or credential exposure are in scope. Mathematical-content disagreements without a security or privacy impact should use an ordinary issue with synthetic examples.