The following versions of this composite GitHub Action are actively supported for security fixes:
| Version | Supported |
|---|---|
| 1.x.x | ✅ |
If you discover a security vulnerability in this extension you may file a private issue with the label security on the GitHub repository: https://github.com/ChantifiedLens/Deploy-Microsoft-Fabric-Items.
Do not open a public issue with PoC code or sensitive details—this could expose users.
We will respond when possible and provide updates on mitigation steps and timelines.
- Use least-privilege for the service principal (grant only the minimal permissions required).
- For extra safety, run your build in a minimal, ephemeral runner.
- We follow a coordinated disclosure model. After acknowledgement, we will provide remediation timeline and patches privately.
- For severe vulnerabilities we will coordinate with the GitHub Marketplace team if required.