Use GitHub's Report a vulnerability feature on the repository Security tab. Do not open a public Issue for leaked credentials, private data, workflow bypasses, or a way to execute untrusted pull-request code.
Include the affected file or workflow, reproduction steps, impact, and a safe remediation suggestion when available. Do not include real customer data or active secrets.
Security reports may cover the validator, preview generator, GitHub Actions permissions, publication integration, content sanitization, or accidental disclosure in repository history. Product service vulnerabilities should be reported through Qoder's official security channel instead of this content repository.
Maintainers will acknowledge a complete report through GitHub, investigate it, and coordinate disclosure after a fix is available.