Security fixes are applied to the current release line.
Use GitHub private vulnerability reporting for security issues involving this repository. Do not post sensitive security details publicly.
Provide only the minimum information needed to understand and reproduce the issue safely.
The default application is static and browser-local. It has no backend, account system, analytics, cookies, or default upload endpoint.
Deployment operators may add services outside this repository; those additions are outside the default security boundary and should be reviewed and disclosed separately.