Private reporting route and support boundary for the auditor, installer, shipped workflows, and release artifacts.
Use GitHub private vulnerability reporting for vulnerabilities in the auditor, installer, starter-kit workflows, or release artifacts. Include the affected version and file, realistic impact, minimal reproduction, and a mitigation when available.
Do not open a public issue containing credentials, exploit details for an unpatched vulnerability, or personal information.
A catalog entry is not maintained by this project and is not a security endorsement. Report vulnerabilities in a listed resource to that resource's maintainers. You may open a normal issue here to flag a dead link, an abandoned project, a misleading description, or a resource that no longer meets the inclusion bar.
Only v1.0.0 and the latest commit on the default branch are maintained. Verify release checksums, pin Actions, review upstream changes, and test defenses in a non-critical repository before deployment.