The current main branch and the v1 Action tag are supported.
Do not open a public issue for a potential vulnerability. Use a private GitHub security advisory with a minimal reproduction and expected impact.
The service does not execute repository code or accept private repositories. Reports involving payment validation, request isolation, or generated response data are especially useful.