SECURITY / DISCLOSURE

Trust starts with limits.

MergeGrounds controls admission. It cannot prove arbitrary software safe, replace expert review, or verify external settings from files alone.

Report a vulnerability

Use GitHub’s private vulnerability reporting on the MergeGrounds repository. Do not open a public issue for an unpatched vulnerability, a bypass, exposed credential, or exploit detail.

Open a private security advisory

What is in scope

  • fail-open behavior in a required gate;
  • evidence replay, subject mismatch, or scope-confusion bypass;
  • control-plane lock or CODEOWNERS bypass;
  • unsafe handling of candidate-controlled paths, files, or environment;
  • workflow permission, action-pinning, and release-integrity failures.

Supported versions

Security fixes target the newest published release. Maintainers may ask reporters to confirm a finding against the current main branch when the fix does not expose additional risk.

Security posture

The portable runner is dependency-free Python and intentionally rejects missing, stale, malformed, timed-out, skipped, or ambiguous evidence. The maximum-assurance architecture additionally requires a protected verifier, isolated execution, authenticated identities, and rulesets outside the candidate’s control.