Security reports are accepted for the current public release, v1.0.0, and the current main branch.
Do not disclose credentials, tokens, private tunnel URLs, or exploitable security details in a public issue. Use GitHub's private vulnerability reporting feature when available, or contact the repository owner privately.
Please include the affected commit/tag, reproduction steps, impact, and any mitigation you have tested.
This project never requires a GitHub PAT for normal public cloning or for the default Kaggle demo.