Only the latest released version of git-kura is currently supported for security fixes.
Older versions are not supported unless explicitly stated otherwise.
Please report security vulnerabilities using GitHub's private vulnerability reporting for this repository.
Do not report security vulnerabilities through public GitHub issues, pull requests, or discussions.
When reporting a vulnerability, please include:
- affected version or commit SHA
- operating system and architecture
- installation method
- a short description of the issue
- minimal reproduction steps, if available
- expected security impact
Security reports should relate to git-kura itself or its release/distribution process.
Examples include:
- unsafe file writes
- path traversal
- arbitrary command execution
- installer vulnerabilities
- checksum or signature verification issues
- compromised release artifacts
- reachable dependency vulnerabilities
General bugs, feature requests, and vulnerabilities in Git, the operating system, shell, editor, or user environment are out of scope unless they create a security issue in git-kura.