This repository primarily contains standards and templates, but security issues can still exist in examples, workflow guidance, artifact handling rules, or repository governance instructions.
Use GitHub private vulnerability reporting when available. If a private channel is unavailable, open a minimal public issue that asks for a private contact path and does not include secrets, exploit details, credentials, or sensitive repository data.
Security reports may cover:
- standards that would cause secret exposure;
- templates that request or retain sensitive data unnecessarily;
- workflow guidance that weakens supply-chain or repository trust boundaries;
- examples that contain credentials or secret-shaped values.
This repository does not provide emergency response for repositories that adopt the standards. Each adopting repository remains responsible for its own runtime, credentials, incident response, and disclosure process.