Small attack surface by design

Controls in place

Hosting and firewall boundary

GitHub operates the Pages hosting network, TLS termination, abuse controls, and infrastructure perimeter. This project has no origin server to expose. GitHub Pages does not let this repository configure a custom web application firewall or arbitrary HTTP response headers. A custom-domain WAF can be added later through a reverse proxy such as Cloudflare, but it is not represented as active today.

Report a vulnerability

Use GitHub's private security-advisory form. Include the affected URL or file, impact, reproduction steps, and a safe proof of concept. Do not post an unpatched vulnerability, credentials, cookies, private exports, or personal information in a public issue. Good-faith research that avoids privacy violations, service disruption, and data destruction is welcome.