Security fixes are applied to the latest commit on main.
Please use the repository's Security tab and choose Report a vulnerability to open a private security advisory. Do not include credentials, student data, private deployment details, or an unredacted proof of concept in a public issue.
Include the affected route or file, impact, reproduction conditions, and a minimal redacted proof of concept when possible. The maintainer will acknowledge a valid report and coordinate a fix before public disclosure.
Environment files, account stores, moderation records, feedback and report data, databases, logs, avatars, and uploaded media are intentionally excluded from Git. Production backups must be encrypted and stored outside the repository.