This repository contains benchmark fixtures and automation rather than a
versioned runtime package. Security fixes are applied to the main branch.
Do not open a public issue for a suspected vulnerability. Use GitHub private vulnerability reporting:
https://github.com/weapp-vite/benchmarks/security/advisories/new
Include the affected workflow or fixture, environment, impact, reproduction steps, and any suggested mitigation. Vulnerabilities in an upstream framework should also be reported to that framework's maintainers.