Security fixes are provided for the latest version on the default branch.
Please do not open a public issue for a suspected security or privacy vulnerability.
Use GitHub's Report a vulnerability / private security-advisory feature for this repository. Include:
- the affected version or commit;
- a clear reproduction using generated, non-sensitive data;
- the expected and observed behavior;
- the potential impact, especially any possible network transmission, persistence, report leakage, or cross-site scripting.
Do not include private CSV data, credentials, personal data, or production files. Maintainers should acknowledge a report within seven days and provide status updates while it is being investigated.
CSV Health is designed with no backend and no intentional transmission of selected CSV contents. Changes that add analytics, remote APIs, uploads, persistence, or logging of source values are security-sensitive and require explicit project review.