Do not open a public issue for a suspected vulnerability. Report it privately
through the repository's GitHub Security Advisory form and mention
@alfaarghya in the report. Include reproduction steps, affected browsers, and
the expected impact.
You should receive an acknowledgement within seven days. Please allow time for the issue to be investigated and fixed before publishing details.
RepoFrame has no backend, accounts, or user database. It runs in the browser and talks directly to GitHub. Relevant reports include unintended data uploads, unsafe handling of repository content, dependency vulnerabilities with a practical impact, and export or storage behavior that exposes local data.