This repository tracks standards and reusable CI workflows. Security fixes are applied on the default branch and included in the next release tag.
| Version | Supported |
|---|---|
| Latest release tag | ✅ |
| Previous minor release | ✅ |
| Older releases | ❌ |
Do not open public issues for vulnerabilities.
Report privately using GitHub Security Advisories:
Include:
- Affected files/workflows and branch or tag
- Reproduction details or proof of concept
- Expected vs actual security behavior
- Impact and suggested remediation
- Initial acknowledgment: within 3 business days
- Triage update: within 7 business days
- Remediation timeline: based on severity and exploitability
After remediation is available, maintainers may publish a coordinated disclosure with impact, fix summary, and upgrade guidance.