| Version | Supported |
|---|---|
| 1.x | ✅ |
We take security seriously. If you discover a security vulnerability in this GitHub Action, please report it responsibly.
- Do not open a public GitHub issue for security vulnerabilities
- Email hello@shiftinbits.com with:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Acknowledgment: Within 48 hours
- Initial Assessment: Within 7 days
- Resolution Timeline: Depends on severity, typically within 30 days
This security policy covers:
- The Constellation Index GitHub Action (
action.yml) - Associated scripts and configuration files in this directory
For vulnerabilities in the Constellation CLI itself, please report to the main repository.
- Pin to a version tag (e.g.,
@v1) rather than@main - Review workflow permissions before enabling
- Audit secrets access in your repository settings
- Enable Dependabot for security updates