Do not place secrets, API keys, tokens, or private URLs into issues, pull requests, or logs.
If you find a security problem:
- Describe the affected file or workflow.
- Explain the impact.
- Include a minimal reproduction if it is safe to do so.
- Prefer a private report channel when one is available.
For local workflows, verify changes with the existing validation scripts before publishing.