This repository is under migration review and is not release-ready.
- API credentials, Compose secrets, registry credentials, build contexts, and event payloads are sensitive.
- The compatibility server must come from an explicitly reviewed URL and is verified against the required exact SHA-256 before execution; it is never fetched by default.
- Build and deployment operations can execute container images and access local files referenced by Compose input.
- The checked-in Dapper OpenVEX applies only to kernel vulnerability identifiers attributed to the build-only
linux-libc-devuser-space headers. The gate requires an exact finding-to-statement match, rejects kernel image or module packages, and separately scans the shipped CGO-disabled binary. - Do not commit credentials, private Compose files, production event payloads, or private artifact URLs.
Report suspected vulnerabilities through this repository's private security advisory channel. Do not include live credentials or private Compose data in a public issue.