This repository hosts a static public-interest policy document plus public evidence materials. There are no servers, no user data, and no authentication.
If you find a security concern with:
- A publicly tracked file that exposes a secret, token, credential, private path, or private working material.
- A release asset that appears to contain private metadata.
- A GitHub Pages configuration issue that serves unintended files.
Please email support@instats.org rather than opening a public issue. You can expect an acknowledgement within 7 days.
- A factual error in the report text or a chart number. Please use the Sourcing question issue template instead.
- A policy disagreement with the report's analysis. That's a different kind of conversation; if grounded in a primary source the report missed, the sourcing-question template still applies.
- A local reproduction problem due to missing dependencies. Please use the Bug report issue template — that's a setup question, not a security concern.
Only the latest release is supported. Previous versions remain tagged and downloadable for archival purposes (citations may pin a specific version), but no security fixes are backported.