Report a vulnerability
Use GitHub’s private vulnerability reporting on the MergeGrounds repository. Do not open a public issue for an unpatched vulnerability, a bypass, exposed credential, or exploit detail.
Open a private security advisory
What is in scope
- fail-open behavior in a required gate;
- evidence replay, subject mismatch, or scope-confusion bypass;
- control-plane lock or CODEOWNERS bypass;
- unsafe handling of candidate-controlled paths, files, or environment;
- workflow permission, action-pinning, and release-integrity failures.
Supported versions
Security fixes target the newest published release. Maintainers may ask reporters to confirm a finding against the current main branch when the fix does not expose additional risk.
Security posture
The portable runner is dependency-free Python and intentionally rejects missing, stale, malformed, timed-out, skipped, or ambiguous evidence. The maximum-assurance architecture additionally requires a protected verifier, isolated execution, authenticated identities, and rulesets outside the candidate’s control.