Security fixes target the current main branch. The stable branch receives
validated changes through the repository's synchronization workflow.
Do not disclose suspected vulnerabilities, exposed credentials, or sensitive host details in a public issue.
Use GitHub's private vulnerability reporting for this repository when available. Otherwise, contact the maintainer privately through the GitHub profile and include:
- the affected host, module, or workflow;
- the expected and observed security boundary;
- reproduction details that do not reveal live credentials; and
- any suggested mitigation.
Never include decrypted Agenix content, private keys, access tokens, or other live secrets in a report.