Security fixes are considered for the current 0.1.x release line and the
default branch. Older versions may not receive fixes.
Use GitHub private vulnerability reporting for suspected vulnerabilities. Do not include active exploit details, secrets, or sensitive workflow content in a public issue.
Include the affected ActionDoc version, impact, reproducible steps or a sanitized workflow, expected and observed behavior, and any known mitigation. Maintainers will assess the report and coordinate disclosure through the private advisory.