Report vulnerabilities privately through the repository's GitHub security advisory page. Do not open a public issue for an undisclosed vulnerability.
Metadata, crawler directives, sitemaps, structured data, and IndexNow payloads are public discovery surfaces. They are not authentication or authorization boundaries. Applications must make access decisions from trusted server-side state and must not publish private facts through these helpers.
Security fixes are supported on the latest release. Include affected versions, reproduction conditions, and impact in a report. Do not include live credentials or private deployment data.