If you discover a security vulnerability, report it responsibly using GitHub Security Advisories.
Do not open a public issue. Public disclosure before a fix is in place puts users at risk.
The maintainer will acknowledge the report within 5 business days and aim to release a fix within 30 days for confirmed vulnerabilities.
Only the latest version on the main branch is supported with security updates.
This tool is a read-only Azure assessment runner. It does not write to Azure resources, store credentials, or transmit data externally. Findings are written locally.
Relevant vulnerability classes include:
- Credential or secret leakage in output files or logs
- Injection vulnerabilities in query or report generation
- Supply chain issues in bundled tool versions
- Workflow injection in GitHub Actions workflows