Do not disclose a suspected vulnerability in a public issue. Use GitHub's private vulnerability reporting and include reproduction steps, affected URLs or commits, impact, and any suggested mitigation.
The portfolio is a static export with no database, authentication, server functions, or contact-form backend. Dependency, workflow, supply-chain, cross-site scripting, and deployment-configuration reports are still relevant. Never include real credentials or private personal data in a report.
Only the latest main revision is supported. Security updates are published through the normal
quality-gated GitHub Pages workflow.