Security fixes target the current main branch. Older commits and derived deployments are not maintained as separate support lines unless a GitHub advisory says otherwise.
Do not open a public issue for an unpatched vulnerability.
Use GitHub private vulnerability reporting. If GitHub is unavailable, email nyk@builderz.dev with the subject Marketing Dashboard security report.
Include the affected route or component, reproduction conditions, likely impact, and any suggested mitigation. Remove credentials, personal data, private hostnames, and unrelated local paths from logs or screenshots.
The maintainers will coordinate validation, remediation, disclosure timing, and reporter credit privately. No response-time guarantee is offered.
Reports are especially useful for authentication bypasses, authorization errors, unsafe writeback, secret exposure, webhook abuse, path traversal, unintended filesystem access, and dependency or release-integrity failures.