Security fixes are applied to the latest commit on main. Users should build or install the newest published release.
Do not publish exploit details in a public issue. Use GitHub's Security → Report a vulnerability private reporting flow for this repository. Include the affected version/commit, browser version, reproduction steps, impact, and any suggested mitigation.
If private vulnerability reporting is temporarily unavailable, open a minimal public issue asking a maintainer to establish a private contact channel; do not include sensitive details.
Filter-list false positives and broken websites are not security vulnerabilities. Report extension behavior to this fork and list-content problems to the relevant list maintainer.