Please do not report security vulnerabilities through public GitHub issues.
- Preferred: use GitHub's private vulnerability reporting on this repository (Report a vulnerability).
- Alternatively, email support@motherduck.com with the details and we will route it to the security team.
Include a description of the issue, steps to reproduce, and the affected version of the md-blueprints package or action if known.
This policy covers the md-blueprints CLI and GitHub Action, the generated customer template, and the workflows in this repository. For the MotherDuck service itself, contact MotherDuck support.
Only the latest release line receives security fixes. Customer repositories should keep their exact action and CLI pins aligned. The scheduled Blueprints Doctor opens an upgrade issue when a newer release exists or those pins drift; Dependabot continues to cover third-party workflow actions.