Security fixes are made on the latest released minor version and on main.
Older releases may be affected even when a fix is straightforward to backport.
Please use GitHub's private vulnerability-reporting form:
https://github.com/CarlSR9001/whetstone/security/advisories/new
Do not open a public issue for an unpatched vulnerability and do not include private exam-bank contents, submitted answers, service credentials, or signing keys in a report. Include the affected version or commit, a minimal reproduction, the security boundary that was crossed, and any known impact.
You should receive an acknowledgement within seven days. A fix timeline depends on severity and whether coordinated disclosure is needed. Credit is offered in the release notes unless you prefer to remain anonymous.
The hosted workbench intentionally loads no private promotion bank. Disposable report-card prompts are public practice material, and Open Promotion Bench system identities are self-attested. Those boundaries are security-relevant: please report any path that exposes persistent private-bank data, raw submitted answers, service credentials, signing keys, or cross-session task material.