Security fixes are applied to the latest release and the main branch.
Do not disclose suspected vulnerabilities in a public issue. Use Report a vulnerability in the repository's Security tab to send the maintainer a private report. If private vulnerability reporting is unavailable, contact the maintainer privately through the ZuhairQuakes GitHub profile before public disclosure.
Include the affected version, reproduction steps, expected impact, and any suggested mitigation. You should receive an acknowledgement within seven days.
Reports about unsafe file parsing, malicious GeoJSON, dependency compromise, credential exposure, or unintended data retention are in scope. USGS service availability and scientific disagreements about third-party earthquake records are not software security vulnerabilities.