If you find a security weakness in this repository, please report it privately. Do not open a public issue — an issue is visible to everyone, including before there is a fix.
Email security@morelitea.com with:
- what you found
- how to reproduce it
- what an attacker could do with it
- a suggested fix, if you have one
- Acknowledgement within 48 hours.
- An estimated timeline once we have reproduced it.
- A note when it is fixed.
- Credit in the release notes, unless you would rather stay anonymous.
This repository covers the GitHub integration service. Reports about its own code, its configuration, and its GitHub Actions workflows are all in scope.
Third-party dependencies are out of scope as such, but a report that a dependency we pin is vulnerable, and reachable from here, is welcome.
| Version | Supported |
|---|---|
| latest | Yes |
This project has not reached a stable 1.0, so fixes go to the latest release.