Do not open a public issue for security vulnerabilities.
Use GitHub's private vulnerability reporting: go to the affected repository's Security tab → Report a vulnerability. This opens a private advisory visible only to maintainers.
If you cannot use that flow, email: platform@zarishsphere.com
Include: affected repo/version, a description of the issue, and reproduction steps if possible. You will get an acknowledgment as soon as practical — this is a solo-maintainer project, so response times may vary, but security reports are the highest priority.
This applies to all repositories under the zsdotcom GitHub organization.
Given this platform's context (health data for displaced populations), any vulnerability touching identity resolution, data export, or the emergency key-destruction protocol should be flagged as critical in your report.