Skip to content

Security: TableProApp/integrations

SECURITY.md

Security

Report a problem

Do not open a public issue for any of these.

What this repository protects

  • Pull request checks run with a read-only token and never see secrets. Labeling runs on pull_request_target and never checks out pull request code.
  • Every action is pinned to a full commit SHA.
  • Entries are pinned to numeric repository and account IDs, so a renamed or re-created repository is caught.
  • Entry data is only parsed, never run. Images are decoded only in CI. SVG is not accepted.

There aren't any published security advisories