The pr-summary maintainers take security seriously. Thank you for helping us keep the project and its users safe.
| Version | Supported |
|---|---|
v0.2.x |
✅ Active |
v0.1.x |
Please do not open a public GitHub issue for security problems.
Use GitHub's private Security Advisories flow:
- Go to https://github.com/wardsvelds2l/pr-summary/security/advisories/new
- Fill in a clear title and a detailed description:
- What is the impact?
- Which version(s) are affected?
- What is the reproduction / proof of concept?
- Are there any workarounds?
- Submit. Only the maintainer team will see the report.
We aim to acknowledge new reports within 72 hours and ship a fix or mitigation within 30 days for high-severity issues, faster for critical ones. We follow coordinated disclosure: please give us a reasonable window before publishing details.
- We do not operate a public security@ mailbox for this project. Use the GitHub Advisories tab.
- We do not accept vulnerability reports via social media, comments on commits, or pull requests.
- We will not pursue legal action against researchers who act in good faith and stay within the coordinated-disclosure window.
- The action sends the unified diff of every pull request to the configured OpenAI-compatible endpoint (
openai-base-url). If your repository's PRs contain secrets in the diff (they shouldn't), those secrets will be sent to the LLM provider. - The action stores nothing; every run is stateless. There is no database, no log shipping, and no telemetry.
- The default
github-tokeninput is the workflow-providedGITHUB_TOKEN, which has read access to the PR diff and write access to issue comments. It does not have write access to the repository contents. - The bundled
dist/index.jsis built fromsrc/using@vercel/ncc; you can verify the build is reproducible withnpm ci && npm run bundleand diffing against the committeddist/.
Researchers who report valid vulnerabilities will be credited in the release notes unless they ask to remain anonymous.