Do not open a public issue for an exposed credential, personal contact detail, privacy concern, malicious file or unsafe automation change.
Use the repository's Security tab and choose "Report a vulnerability" to open a private security advisory. Identify the affected path or revision without copying sensitive data into the report. If private vulnerability reporting is unavailable, contact the repository owner privately and disclose only enough information to establish a safe reporting channel.
Do not submit private correspondence, credentials, signatures, home addresses, phone numbers, unpublished third-party work or another person's likeness or story material without clear permission.
If sensitive information was committed, removing it from the current file is insufficient. Revoke affected credentials, remove the current copy, inspect generated PDFs and media, and rewrite reachable Git history before making the repository public.
Security and privacy corrections apply to the current main branch. Historical story drafts are preserved only when they are safe and lawfully shareable.