Do not open a public issue for vulnerabilities. Report security concerns through a
private GitHub security advisory for this repository. If advisories are unavailable,
contact the current maintainers listed in CODEOWNERS and request a private
reporting channel.
Include:
- affected files or workflows
- reproduction steps
- expected impact
- whether generated harness files or
.agent-workartifacts are affected
The supported version is the current main branch until the first tagged release.
After tagged releases begin, supported versions are listed in CHANGELOG.md.
This repository does not ship a runtime library. Security review focuses on:
- GitHub Actions permissions and third-party actions
- generated instruction files
- portable workflow instructions
- repository governance files
- supply-chain dependency updates