Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Security

See SECURITY.md for how to report a vulnerability.

Private reports go through GitHub Security Advisories. Release archives include Cosign .sigstore.json and SLSA .intoto.jsonl assets. The Release workflow also uploads a CycloneDX SBOM, canact-sbom.cdx.json. Git release tags are GPG-signed annotated tags (git verify-tag vX.Y.Z).