This is a documentation repo. There is no code to exploit, but there are two things worth reporting fast.
Wrong or dangerous guidance. If something in here would make a company less safe by following it, open an issue. That is a bug with a blast radius, and it jumps the queue.
Anything that looks client-identifiable. Nothing here should come from a real engagement. If you spot something that looks like it did, do not open a public issue. Use GitHub's private vulnerability report on this repo, or the contact on my profile, and it gets handled quietly and quickly.
No bounty program. The reward is that the next company to use this is safer, plus a thank-you in the commit.