Use GitHub's private vulnerability reporting for this repository: https://github.com/somework/lockrot-action/security/advisories/new. Do not open a public issue. You will get an acknowledgement within a few days, and a fix or an explanation before anything is published.
If the problem is in lockrot itself rather than in this action or the image, report it at https://github.com/somework/lockrot/security/advisories/new instead.
- GitHub Releases of
somework/lockrotforlockrot.pharandlockrot.phar.sha256. The default release is pinned by version and sha256 inlockrot.env; a download that does not match is refused. An explicitversiontrusts the.sha256file from the same release, and thechecksuminput replaces both. actions/cacheandshivammathur/setup-php, pinned by commit SHA inaction.yml.- The token in
github-tokenis handed to lockrot, which uses it againstapi.github.comonly.
The same release assets, fetched and verified at build time, on the official php image pinned by
digest. Every published image is signed with cosign through GitHub's OIDC identity and carries a
GitHub build-provenance attestation; the README shows how to verify both.
The newest v1.x.y release, which v1 follows. Older releases keep working but are not patched.