Do not report security vulnerabilities in public issues or discussions.
Use the repository's private vulnerability reporting form. For a vulnerability in the Briosa server or protocol, report it privately in the Briosa server repository.
The documentation site is static and receives no credentials. Pull-request
workflows are read-only, use GitHub-hosted runners, and receive no deployment
permissions. Only the protected main branch may deploy to GitHub Pages.