Use GitHub's private vulnerability reporting for this repository. Do not disclose an unpatched vulnerability in a public issue.
Include the affected path or runtime version, reproduction steps, expected impact, and any suggested mitigation. Do not include credentials, customer data, or production exports.
The demo contains only synthetic data. A report that depends on customer or production data is outside the intended design and should still be submitted privately.
Security fixes apply to the current main branch and the latest published deployment artifact. Older source revisions are not supported.