shift-rota is an offline, local command-line tool. It reads only the CSV files you point it at and writes only to the --out directory you choose. It makes no network requests and stores no credentials.
Please open a private security advisory or contact the repository owner via GitHub with:
- a description of the issue,
- steps to reproduce,
- the impact you expect.
Please do not include real employee personal data in public issues — use synthetic names.
Staff CSVs may contain real names and availability. They are never uploaded anywhere by this tool; keep them out of public Git repositories (.gitignore your working data, or use the synthetic examples provided).