Do not open a public issue for a vulnerability that could expose visitors, credentials, unpublished evidence, or upstream services. Use GitHub’s Report a vulnerability form under the repository’s Security tab. If private reporting is unavailable, contact the repository owner through the address on their GitHub profile and ask for a secure channel without including exploit details in the first message.
Include the affected URL or revision, impact, reproduction steps and any safe mitigation you have tested. Reports will be acknowledged as soon as practical.
The publication is static, but security still includes cross-site scripting, supply-chain changes, compromised data provenance, unsafe external requests, secret exposure, deployment permissions and ways to misrepresent evidence.
Please report data or scientific errors through the normal issue templates unless disclosure itself would create a material risk.