Skip to content

Security: sonofmagic/repoctl

Security

SECURITY.md

Security Policy

English | 简体中文

Supported versions

Security fixes are provided for the latest stable major release of repoctl and its fixed-version core package. Upgrade to the latest release before reporting a problem that may already be resolved.

Reporting a vulnerability

Do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting for sonofmagic/repoctl:

https://github.com/sonofmagic/repoctl/security/advisories/new

Include the affected version, environment, impact, reproduction steps, and any suggested mitigation. Maintainers will acknowledge a complete report as soon as practical and coordinate validation, remediation, and disclosure with the reporter.

Scope

Reports involving repoctl command execution, generated workflow security, release credentials, dependency handling, path traversal, or unsafe template extraction are in scope. Vulnerabilities in third-party tools should also be reported upstream when appropriate.

There aren't any published security advisories