This document outlines suggested security procedures for handling security issues concerning the actions.
If you've found a security vulnerability in a GitHub action, please do not create an issue on the GitHub issue tracker as it will be visible publicly.
Instead, send an email to the main contributors for the action.