Skip to content

Latest commit

 

History

History
18 lines (12 loc) · 538 Bytes

File metadata and controls

18 lines (12 loc) · 538 Bytes

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability, please report it privately:

  1. Do NOT open a public GitHub issue
  2. Use GitHub's private vulnerability reporting feature
  3. Include: description, reproduction steps, and impact assessment

We aim to respond within 48 hours and release a fix within 7 days for critical issues.

Scope

  • Command injection via config values
  • Privilege escalation during install
  • Unsafe temporary file handling
  • Supply chain risks in default template URLs