Security policy¶
Reporting a vulnerability¶
Report suspected vulnerabilities privately through GitHub's security advisories: the Security tab of this repository, then "Report a vulnerability." Do not open a public issue, pull request, or discussion for a suspected vulnerability before it has been triaged.
This repository holds standards, checks, and scripts rather than a running application, so the likely findings are flaws in the scripts, the hooks, or the rules themselves, and those are welcome through the same private path. A useful report includes the affected file, the impact as you understand it, and reproduction steps. Do not include real credentials in a report.
Supported versions¶
Fixes land on the latest commit of the main branch.