Please do not open a public issue for security problems.
Report privately through GitHub's private vulnerability reporting: https://github.com/ojspace/soloteam-cli/security/advisories/new
You will get an acknowledgement within 7 days. Once the report is confirmed, a fix is prioritised and an advisory is published together with the patched release. Please give us a reasonable window to ship a fix before public disclosure.
In scope:
- Code in this repository on the default branch and in published releases
- Supply-chain issues in dependencies declared here that are exploitable through this project
Out of scope:
- Vulnerabilities in third-party services or tools this project only calls
- Issues that require a compromised local machine or already-elevated access
- Findings from automated scanners without a demonstrated impact
- Affected version or commit
- Steps to reproduce, or a proof of concept
- Impact: what an attacker can do
- Any suggested mitigation
Only the latest release receives security fixes.