Security fixes are applied to the current main branch and the production deployment at asteroidmap.com.
Use GitHub's private vulnerability reporting feature for this repository. If that feature is unavailable, email go@ziplyne.agency with the subject Asteroid Map security report.
Include the affected URL or commit, reproduction steps, impact, and any suggested mitigation. Do not include secrets or personal data beyond what is necessary to reproduce the issue, and do not open a public issue until the report has been resolved or disclosure has been coordinated.