The current development version is supported.
Please report vulnerabilities through the repository's private security advisory form:
https://github.com/yzf121/actions-permission-diff-ledger/security/advisories/new
Do not include working secrets, private workflow contents, or exploit details in a public issue.
Actions Permission Diff Ledger is a static local analyzer. It does not execute workflows, does not call external services, does not read secret values, and does not require tokens.
Git-ref mode invokes the local git executable without a shell, resolves refs to commits, and materializes only bounded workflow blobs. Public reports sanitize local paths, credential-bearing URLs, token patterns, control characters, and raw dangerous commands.
Findings are review evidence. They indicate trust-boundary changes that deserve human review. They are not proof that a workflow is exploitable.