Security fixes are applied to the latest published minor release. Version 0.x is an evolving API; upgrade to the newest release before reporting a resolved issue.
Use the repository's GitHub Security → Report a vulnerability form. Do not open a public issue for path traversal, crafted HWPX or image payloads, privacy leaks, or secret exposure.
Include the affected version, operating system, Python version, a minimal synthetic reproduction, impact, and suggested mitigation. Remove personal data, real exam content, credentials, and private file paths before sending a report.
Security reports may cover asset sandbox escapes, unsafe output behavior, unexpected network access, receipt path disclosure, malformed-package handling, or dependency vulnerabilities with a demonstrated path through this package.
Content accuracy, copyright disputes, answer-key secrecy, DRM, malware detection, and pixel-perfect rendering are outside this project's security guarantees.