Only the latest release is supported. If you're not on the latest tag, please upgrade before reporting an issue.
Please use GitHub's private vulnerability reporting (Security tab → "Report a vulnerability") instead of a public issue. This applies to the linter itself - e.g. something in SourceExtractor or BeanshellSyntaxChecker that could be made to hang, crash unsafely, or execute unintended code when fed a malicious XML/BeanShell input, or a supply-chain concern with the vendored BeanShell jar.
This does not cover findings the linter's rules produce or fail to produce against your own SailPoint IIQ code - those are correctness/false-positive issues, not security reports about this project, and belong in a regular issue.
We'll acknowledge reports within a few days and aim to have a fix or mitigation out within 2 weeks for anything confirmed, sooner for anything severe.