Rulepath is a security-adjacent static analysis tool. Please report vulnerabilities responsibly.
Open a private security advisory if available, or contact the maintainers before publishing details.
Include:
- Affected version or commit.
- Reproduction steps.
- Impact.
- Suggested fix if known.
Security reports may include crashes on crafted repositories, unsafe file writes, incorrect CI-failure behavior, suppression bypasses, or vulnerabilities in generated artifacts.
False negatives and false positives are important, but should usually be reported with the false-positive or false-negative issue template.