If you find a vulnerability in any Envisioning repository, email contact@envisioning.com. Do not open a public issue.
Include the repo, steps to reproduce, and impact as you understand it. We reply within a few working days and credit reporters in the fix unless asked not to.