Readme · Code of Conduct · Contributing · Support · License
Caution
Do not open a public issue, discussion, or pull request to report a security vulnerability. Use the private channels listed below.
| Channel | Details |
|---|---|
| Email (preferred) | security@octalmesh.com |
| Direct contact | Reach a core maintainer directly |
The more context you provide, the faster and more accurately we can triage.
- Type of issue - e.g. command injection, token leakage, path traversal
- Affected surface -
src/file(s), action inputs, or handler behavior - Location - repository, branch, commit, or direct URL if public
- Environment - Node, pnpm, OS, event payload used
- Reproduction steps - minimal workflow or event payload to reproduce
- Proof-of-concept - exploit code or demonstration, if available
- Impact - realistic scenarios and risk to CI/CD pipelines
Incomplete reports are still welcome, but detailed reports allow faster and more accurate triage.
- English
- Ukrainian
- Russian
This policy covers vulnerabilities in the belay-action repository, including
the action code under src/, the published dist bundle, and the action's
inputs and handlers.
Note
Issues in third-party dependencies should also be reported to their respective maintainers when applicable.
| Stage | Target |
|---|---|
| Acknowledgement | Within 48 hours |
| Initial assessment | Within 5 business days |
| Fix & disclosure | As soon as reasonably possible |
Timelines may vary depending on severity and complexity.