If you discover a security vulnerability in this GitHub Action, please report it responsibly.
Do not open a public issue.
Instead, email security@prodcycle.com with:
- A description of the vulnerability
- Steps to reproduce
- Potential impact
We will acknowledge your report within 2 business days and aim to provide a fix within 7 days for critical issues.
This policy covers the prodcycle/actions GitHub Actions code. For vulnerabilities in the ProdCycle API or platform, please report those separately at prodcycle.com/security.
- Never commit your
pc_API key to source code - Always use GitHub encrypted secrets to store your ProdCycle API key
- The action automatically masks the API key in workflow logs