Please do not disclose security vulnerabilities in a public issue or pull request. Use GitHub private vulnerability reporting for this repository. If that channel is unavailable, contact the organization maintainers privately through GitHub and include only the minimum information needed to reproduce the problem.
Include the affected repository or workflow, revision, impact, reproduction steps, and a suggested mitigation when known. Redact credentials, tokens, private paths, and personal data. We will acknowledge reports as soon as practical, coordinate a fix, and publish any necessary follow-up once it is safe to do so.