This repository is historical educational material, not a supported production service. Security reports are still accepted for the current default branch and the workshop step branches when they identify host compromise, data exposure, or an unsafe pattern presented as recommended practice.
Deployments, forks, and missing production hardening such as authentication or rate limiting are outside scope unless the workshop code introduces a distinct vulnerability.
Report suspected vulnerabilities through GitHub private vulnerability reporting. Do not open a public issue.
Include the affected branch, environment, reproduction steps, and impact. Do not include credentials or personal data. Remediation and disclosure will be coordinated through the private advisory.