| Version | Supported |
|---|---|
| 0.1.x | ✅ |
If you discover a security vulnerability within gh-inspector, please send an email to the maintainers. All security vulnerabilities will be promptly addressed.
Please do not report security vulnerabilities through public GitHub issues.
When reporting a vulnerability, please include:
- A description of the vulnerability
- Steps to reproduce the issue
- Potential impact of the vulnerability
- Any potential solutions (if known)
- We will acknowledge receipt of your vulnerability report within 48 hours
- We will provide a detailed response within 7 days, including steps we plan to take
- We will work to resolve critical vulnerabilities as quickly as possible
When using gh-inspector:
- GitHub Authentication: This tool uses GitHub CLI (
gh) for authentication. Ensure yourghcredentials are secured. - Dependencies: Keep the tool and its dependencies up to date.
- Rate Limiting: Be aware of GitHub API rate limits when querying large organizations.
- We follow responsible disclosure practices
- Security issues will be publicly disclosed after a fix is available
- Credit will be given to security researchers who report issues responsibly
Thank you for helping keep gh-inspector and its users safe!