Please report security vulnerabilities privately through GitHub Security Advisories. Do not open a public issue or pull request for an undisclosed vulnerability.
If GitHub Advisories are unavailable, email j.d.a.jewell@open.ac.uk with the subject Security report: launch-scaffolder. Include the affected version or commit, impact, and reproducible steps. Please do not include secrets belonging to other people.
The maintainer aims to acknowledge reports within 48 hours and provide an initial triage within seven days. Fix and disclosure timing will be coordinated with the reporter; these are targets, not guarantees.
Security fixes target the latest code on main. Older generated launchers are not automatically updated; re-mint them with a current launch-scaffolder release.