Skip to content

Security: yzf121/actions-permission-diff-ledger

Security

SECURITY.md

Security Policy

Supported versions

The current development version is supported.

Reporting a vulnerability

Please report vulnerabilities through the repository's private security advisory form:

https://github.com/yzf121/actions-permission-diff-ledger/security/advisories/new

Do not include working secrets, private workflow contents, or exploit details in a public issue.

Project safety model

Actions Permission Diff Ledger is a static local analyzer. It does not execute workflows, does not call external services, does not read secret values, and does not require tokens.

Git-ref mode invokes the local git executable without a shell, resolves refs to commits, and materializes only bounded workflow blobs. Public reports sanitize local paths, credential-bearing URLs, token patterns, control characters, and raw dangerous commands.

What findings mean

Findings are review evidence. They indicate trust-boundary changes that deserve human review. They are not proof that a workflow is exploitable.

There aren't any published security advisories