Security fixes are applied to the current production deployment and the latest version of the main branch. Older commits and forks are not supported.
Please report suspected vulnerabilities privately by emailing hi@amir.sh.
Include, when possible:
- A description of the issue and its potential impact
- The affected URL, component, or commit
- Steps or a proof of concept that reproduce the issue
- Any suggested remediation
Do not include sensitive details in a public GitHub issue or pull request. Please allow a reasonable amount of time to investigate and address a confirmed issue before public disclosure.
For non-security bugs and feature requests, use the GitHub issue tracker.