Report it privately, with "Report a vulnerability" on the repository's Security tab. Do not open a public issue for it. Say what an attacker can do, and how to reproduce it.
Fixes go into the latest release.
- It runs as you, on your systemd user manager, and does not need root.
- A project's yaml, its
.envand its build steps run with your rights. Runningupin a directory runs that project's programs, as runningmakethere would. - The rendered unit files may hold environment values. They are readable by you alone, in a directory only you can write to.