Please do not report security vulnerabilities in a public issue.
Use GitHub's private vulnerability reporting from the repository's Security page. Include a description, reproduction steps, and the impact you expect. The report is shared privately with the Supaclank maintainers so we can coordinate disclosure after a fix is available.
If GitHub's reporting form is unavailable, email security@supaclank.com.
The values prefixed with PUBLIC_, the Supabase publishable key, analytics configuration, and browser-facing form endpoints are intentionally public. Never submit private keys, service-role keys, access tokens, or deployment credentials to this repository.