Only the latest release on the main branch receives security fixes.
Because this application stores all data locally in the browser and makes no network requests to any backend, the attack surface is limited. However, if you discover a security issue — such as a cross-site scripting vulnerability in the report rendering, an unsafe use of eval, or a dependency with a known CVE — please report it responsibly.
Do not open a public GitHub Issue for security vulnerabilities. Instead, please email the maintainers directly or use GitHub's private vulnerability reporting feature (Security → Report a vulnerability) on the repository page.
We will acknowledge the report within 72 hours and aim to release a fix within 14 days for confirmed issues.