Security fixes target the deployed portfolio and the current default branch. Older commits and forks are not supported.
Please report suspected vulnerabilities privately to qwezdi@proton.me. Do not open a public issue for an unresolved vulnerability.
Include the affected route or component, impact, reproduction steps, and any safe supporting evidence. Never include passwords, API keys, session tokens, or other secret values in a report.
Reports are acknowledged on a best-effort basis. This policy covers the portfolio application and its public API routes; third-party services should be reported to their respective maintainers.