incus-gh-runner uses GitHub private vulnerability reporting for security issues.
Until the first stable release, only the latest commit on the default branch is supported.
Report vulnerabilities privately through this repository's GitHub private vulnerability reporting flow.
Do not use public GitHub issues, pull requests, discussions, chat channels, or other public forums for vulnerability reports.
When reporting a vulnerability, include as much of the following as possible:
- affected version, commit, or deployment identifier
- a description of the issue and the security impact
- steps to reproduce or a minimal proof of concept
- any relevant logs, screenshots, or traces
- any suggested mitigations or fixes, if available