GH-Guard is a documentation-only Claude Code plugin — it generates configuration files but contains no executable code or runtime dependencies. Security issues in gh-guard primarily manifest as:
- Template defects — workflow templates with insecure patterns (missing permissions, unpinned actions, script injection vectors)
- Stale SHA pins — outdated action SHAs that miss security patches
- Incorrect guidance — skills or commands that recommend insecure practices
If you discover a security issue in gh-guard templates or guidance:
- Preferred: Open a GitHub Security Advisory
- Alternative: Email the maintainers directly
- Acknowledgment: within 48 hours
- Assessment: within 7 days
- Fix: template/guidance fixes released as a patch version bump
| Version | Supported |
|---|---|
| 0.2.x | Yes |
| < 0.2.0 | No |