Security fixes are provided for the latest released version of sisakulint. Older releases should be upgraded before a vulnerability is reported against them.
| Version | Supported |
|---|---|
| Latest release | Yes |
| Older releases | No |
Please do not disclose suspected vulnerabilities in a public issue or pull request. Use GitHub's private vulnerability reporting form for this repository:
https://github.com/sisaku-security/sisakulint/security/advisories/new
Include the affected version or commit, reproduction steps, expected impact, and any suggested mitigation. Reports about bypasses that can cause sisakulint to miss a security-sensitive GitHub Actions pattern are also in scope.
We aim to acknowledge a report within three business days and provide an initial assessment within seven business days. We will coordinate disclosure with the reporter after a fix is available.