PINBAN is currently pre-1.0. Security fixes target the latest main branch until the first stable release policy is defined.
Please do not open a public issue for vulnerabilities that expose private files, arbitrary code execution, dependency compromise or data exfiltration.
Use GitHub private vulnerability reporting when available, or contact the repository maintainers privately through the repository owner profile.
The current demo processes files in the browser. Uploaded artwork should remain local unless a contributor adds network upload behavior. Changes that transmit files, order data or user identifiers must be clearly documented and reviewed carefully.
Never commit real customer artwork, order exports, phone numbers, addresses, pricing records or production photos.