Skip to content

Security: tooppoo/git-kura

SECURITY.md

Security Policy

Supported Versions

Only the latest released version of git-kura is currently supported for security fixes.

Older versions are not supported unless explicitly stated otherwise.

Reporting a Vulnerability

Please report security vulnerabilities using GitHub's private vulnerability reporting for this repository.

Do not report security vulnerabilities through public GitHub issues, pull requests, or discussions.

When reporting a vulnerability, please include:

  • affected version or commit SHA
  • operating system and architecture
  • installation method
  • a short description of the issue
  • minimal reproduction steps, if available
  • expected security impact

Scope

Security reports should relate to git-kura itself or its release/distribution process.

Examples include:

  • unsafe file writes
  • path traversal
  • arbitrary command execution
  • installer vulnerabilities
  • checksum or signature verification issues
  • compromised release artifacts
  • reachable dependency vulnerabilities

General bugs, feature requests, and vulnerabilities in Git, the operating system, shell, editor, or user environment are out of scope unless they create a security issue in git-kura.

There aren't any published security advisories