Skip to content

Latest commit

 

History

History
18 lines (10 loc) · 1.08 KB

File metadata and controls

18 lines (10 loc) · 1.08 KB

Security Policy

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Include a description of the issue, steps to reproduce, and the affected version of the md-blueprints package or action if known.

Scope

This policy covers the md-blueprints CLI and GitHub Action, the generated customer template, and the workflows in this repository. For the MotherDuck service itself, contact MotherDuck support.

Supported versions

Only the latest release line receives security fixes. Customer repositories should keep their exact action and CLI pins aligned. The scheduled Blueprints Doctor opens an upgrade issue when a newer release exists or those pins drift; Dependabot continues to cover third-party workflow actions.