English | 简体中文
Security fixes are provided for the latest stable major release of repoctl and its fixed-version core package. Upgrade to the latest release before reporting a problem that may already be resolved.
Do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting for sonofmagic/repoctl:
https://github.com/sonofmagic/repoctl/security/advisories/new
Include the affected version, environment, impact, reproduction steps, and any suggested mitigation. Maintainers will acknowledge a complete report as soon as practical and coordinate validation, remediation, and disclosure with the reporter.
Reports involving repoctl command execution, generated workflow security, release credentials, dependency handling, path traversal, or unsafe template extraction are in scope. Vulnerabilities in third-party tools should also be reported upstream when appropriate.