Security fixes are accepted against the default branch (master) of this repository.
Please do not open a public Issue for security vulnerabilities that could be exploited (for example XSS via untrusted image URLs, supply-chain issues, or dependency CVEs with exploit detail).
Instead:
- Contact the repository owner via GitHub private vulnerability reporting (if enabled), or
- Open a minimal private channel (owner email / security advisory) describing impact and reproduction without a full exploit PoC if possible.
You should receive an acknowledgment when maintainers are available. We aim to triage within a reasonable window for a small open-source demo project.
Rendering quality bugs, crashes during painting, and documentation gaps belong in normal Issues.