| Version | Supported |
|---|---|
v1.x |
Yes |
main |
Best effort |
| Older tags | No |
If you find a security issue in SquidGate:
- Do not open a public issue for exploitable bugs.
- Contact maintainers via squidoffense.com / SquidSec org.
- Include: description, impact, repro, suggested fix.
We aim to acknowledge within 72 hours.
In scope: secret leakage from the action, unsafe handling of untrusted PR content, supply-chain issues in dist/.
Out of scope: LLM false negatives/positives (model quality), third-party provider issues.
Good-faith research that follows this policy is welcome.