This repository is a continuously deployed website — only the main branch
receives fixes, including security fixes.
Please do not open a public issue for security vulnerabilities.
- Use GitHub private vulnerability reporting to file a confidential report, or
- Email the maintainer listed on MAINTAINERS.md if private reporting is unavailable.
Include a description of the issue, steps to reproduce, and the potential impact. You can expect an acknowledgement within a few days; the project is maintained by volunteers, so timelines for fixes vary with severity.
This policy covers the site source, build scripts, and GitHub Actions workflows in this repository. Vulnerabilities in third-party dependencies should also be reported here if no fixed version is available — Dependabot and automated scanning handle routine dependency advisories.