Please do not report vulnerabilities in a public issue. Use GitHub private vulnerability reporting so the report and any student-data implications remain confidential.
Do not include real student data, NFC UIDs, .env contents, database dumps, Firebase database secrets, or service-account keys in a report. The Firebase web configuration is intentionally public; server credentials are not.
Supported security fixes target the latest main branch.