Security fixes apply to the maintained public release.
Use GitHub private vulnerability reporting for security issues involving this repository or its public validation and release controls.
Do not post sensitive security details publicly. Provide only the minimum information necessary to reproduce the issue safely.
FIW includes baseline safeguards for repository contents, workflow integrity, portable paths, common credential patterns, local user paths, manifests, and deterministic release artifacts.
These controls are not a substitute for security architecture appropriate to a deployment environment.