Only the latest major-compatible action release and its default Shuck version receive security fixes.
Do not report vulnerabilities in a public issue. Use GitHub private vulnerability reporting for ewhauser/shuck-action. Include the affected action and Shuck versions, runner platform, impact, and reproduction steps.
Security issues in the linter itself should be reported through the Shuck security policy.