| Version | Supported |
|---|---|
| latest | Yes |
If you discover a security vulnerability, please report it responsibly:
- Do not open a public issue
- Email the maintainers with details of the vulnerability
- Include steps to reproduce the issue if possible
- Allow reasonable time for a fix before public disclosure
We aim to acknowledge reports within 48 hours and provide a fix or mitigation plan within 7 days.
Security concerns for this project include:
- Hash collision or integrity bypass in the content-addressed store
- Path traversal in pack creation or blob storage
- Arbitrary code execution during replay
- Information disclosure through pack metadata