This repository contains static analysis queries. They don't run in your application, so false positives and missed vulnerabilities are regular bugs: please report them as issues.
Found a vulnerability in openapi-backend itself? Report it privately through openapi-backend's security advisories. Its SECURITY.md and threat model explain what counts.
Found a problem with this repository's release pipeline or packs (for example a tampered pack on GHCR)? Report
it privately through this repository's security advisories,
or email support@openapistack.co with SECURITY in the subject line.