gh-runnerd is in planning; no production-safe release is available. Read the security design before developing providers or authentication.
Do not post secrets or exploit details in a public issue. Use the repository's private vulnerability reporting feature when available. For non-sensitive architectural concerns, open an issue with a sanitized reproduction.
The first native macOS provider is intended only for explicitly trusted repositories and a shared trust domain; it is not a sandbox.