Please report suspected vulnerabilities privately through GitHub Security Advisories. Do not open a public issue or include sensitive details in a pull request.
Include the affected URL or file, reproduction steps, expected impact, and any suggested mitigation. Maintainers will acknowledge a report as soon as practical and coordinate disclosure after a fix is available.
The deployed site and the current main branch are supported. Historical
commits and third-party datasets linked by the catalog are outside this
project's security support boundary.
This repository builds a public static catalog. It does not store datasets, accounts, credentials, or user-submitted data. Reports about an upstream data provider should be sent to that provider unless the issue is caused by this application or its validation workflow.