Please do not open a public issue for a security vulnerability. Contact the repository owner privately through GitHub with:
- a short description of the issue
- steps to reproduce it
- the affected area or files
- any suggested mitigation
Never include passwords, API keys, database URLs, or private book source material in an issue or pull request.
The repository intentionally excludes .env files, credentials, imported private assets, and generated private publishing material. If sensitive material is committed by mistake, revoke or rotate the credential first, then report the incident privately.