Security Policy
Supported Versions
| Version | Status |
|---|---|
| v3.7.1 | Supported |
| Earlier versions | Best-effort only |
The current release index is v3.7.1/. The implementation path remains
v3.5/ for compatibility.
Reporting a Vulnerability
Please report vulnerabilities through GitHub Security Advisories for this repository. Do not file public issues for suspected vulnerabilities.
Include:
- affected path or command,
- expected impact,
- reproduction steps,
- any logs or artifacts needed to verify the issue.
Test Fixtures
This repository includes validation fixtures, including intentionally fake
secret-like strings used to test detection behavior. They are not credentials.
The repository-level GitGuardian configuration is in .gitguardian.yml.
CI and Workflow Safety
Security-sensitive changes, especially GitHub Actions or validator changes, should describe injection, permission, and skipped-gate risks in the PR. The v3.5 release history includes an R-C1 GitHub Actions label-injection hotpatch; keep that regression class in mind when editing workflow logic.