Skip to content

Add a security policy and private reporting links - #12

Merged
Commanderx-code merged 1 commit into
mainfrom
docs/security-policy
Sep 25, 2026
Merged

Commanderx-code merged 1 commit into
mainfrom
docs/security-policy

Conversation

@Commanderx-code

Copy link
Copy Markdown
Owner

Change

Anyone who found a vulnerability could only report it in a public issue. Private vulnerability reporting is now enabled in the repository settings, and this PR points reporters to it:

  • SECURITY.md explains how to report privately through GitHub (Security → Report a vulnerability) and what to include. It covers:
    • Supported versions: only the latest release (0.7.x) gets security fixes.
    • Scope: untrusted repositories, remotes, setup bundles and imports; leaks of credentials or private data; ways around command review; release packaging and CI.
    • Out of scope: attacks that already need code running as your user or as root, commands you approved yourself, and Commander Toolbox scripts, which are reported to that repository.
  • .github/ISSUE_TEMPLATE/config.yml adds a "Report a security vulnerability" link to the new-issue chooser. The existing bug and feature templates and blank issues are unchanged.
  • CONTRIBUTING.md says not to report vulnerabilities in public issues and links to SECURITY.md.

Validation

  • Private vulnerability reporting shows {"enabled":true} through the API.
  • The issue template config parses.
  • npm run check: passed.

Review notes

  • The policy doesn't promise a response time. If you want one, for example "acknowledged within 7 days", add it under "Reporting a vulnerability".
  • When a new minor version ships, update the Supported versions table, for example to 0.8.x.

🤖 Generated with Claude Code

SECURITY.md directs vulnerability reports to GitHub private vulnerability
reporting (now enabled), lists supported versions and describes what is in
scope for a local app that handles untrusted repositories, remotes and
setup bundles. The new-issue chooser and CONTRIBUTING.md point there too.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Commanderx-code
Commanderx-code merged commit c137e5c into main Sep 25, 2026
14 checks passed
@Commanderx-code
Commanderx-code deleted the docs/security-policy branch September 25, 2026 17:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant