Report vulnerabilities privately through GitHub's Report a vulnerability feature.
This template intentionally contains no real hosts, usernames, keys, account IDs, or application secrets. Treat deployment workflows as privileged production code: pin or review third-party actions, protect environments, rotate keys, and keep the deployment account least-privileged.