Only the newest stable PatchPilot Action release receives security fixes.
Use GitHub's private vulnerability reporting for this repository. Do not open a public issue for a suspected vulnerability and do not include customer contracts, source code, tokens, webhook payloads, or other confidential data in an issue.
Include the affected release or commit, impact, minimal reproduction, and any suggested remediation. PatchPilot will acknowledge a complete report as soon as practical and coordinate disclosure after a fix is available.
The Action runs inside the customer's GitHub-hosted or self-hosted runner. It does not send contract or source contents to the PatchPilot control plane. GitHub App orchestration sends only repository identity and signed pull-request coordinates to the workflow.