Do not report vulnerabilities through a public issue.
Use GitHub's private vulnerability reporting feature for this repository. Include the affected workflow and version, the caller-controlled input or trust boundary involved, and a minimal reproduction when safe to provide.
Supported versions are the latest release and the current main branch. Callers remain responsible for updating their
pinned workflow commit after reviewing a new release.