English | 简体中文
Security fixes are considered for the current main branch and, when
available, the most recent published release.
If the repository's Report a vulnerability option is available, use it to submit a private report. Do not include vulnerability details, proof-of-concept code, credentials, or other sensitive material in a public issue.
If private vulnerability reporting is not enabled, open a public issue only to request a secure contact channel. Do not include technical details of the vulnerability in that issue.
Reports about generated HTML, dependency loading and integrity checks, MapSpec validation, or accidental exposure of sensitive data are in scope. Please include the affected revision, a minimal reproduction, impact, and any proposed mitigation through the private channel.