Skip to content

Security: ojspace/soloteam-cli

SECURITY.md

Security Policy

Reporting a vulnerability

Please do not open a public issue for security problems.

Report privately through GitHub's private vulnerability reporting: https://github.com/ojspace/soloteam-cli/security/advisories/new

You will get an acknowledgement within 7 days. Once the report is confirmed, a fix is prioritised and an advisory is published together with the patched release. Please give us a reasonable window to ship a fix before public disclosure.

Scope

In scope:

  • Code in this repository on the default branch and in published releases
  • Supply-chain issues in dependencies declared here that are exploitable through this project

Out of scope:

  • Vulnerabilities in third-party services or tools this project only calls
  • Issues that require a compromised local machine or already-elevated access
  • Findings from automated scanners without a demonstrated impact

What to include

  • Affected version or commit
  • Steps to reproduce, or a proof of concept
  • Impact: what an attacker can do
  • Any suggested mitigation

Supported versions

Only the latest release receives security fixes.

There aren't any published security advisories