Skip to content

Security: Commanderx-code/command-center

SECURITY.md

πŸ” Security policy

How to report a vulnerability in Command Center, and what counts as one.

🏠 README Β Β·Β  πŸ“š Docs Β Β·Β  🀝 Contributing


πŸ›‘οΈ Report a vulnerability privately

πŸ“¨ Reporting a vulnerability

Please report vulnerabilities privately through GitHub: Report a vulnerability (Security tab β†’ Report a vulnerability).

Caution

Don't open a public issue, discussion, or pull request for a security problem.

Include what you can:

  • the Command Center version (Settings β†’ About & updates) and your distribution;
  • what an attacker controls and what they gain;
  • steps to reproduce, or a proof of concept;
  • any fix you'd suggest.

You'll get a reply in the private advisory. Once a fix is ready, it ships in a patch release, and the advisory is published with credit to you unless you'd rather stay anonymous. Please keep the details private until then.

πŸ—“οΈ Supported versions

Important

Security fixes go into the latest release only. Update to the newest version before reporting, and check whether the problem still occurs.

Version Supported
0.7.x (latest) βœ…
Older ❌

🎯 Scope

Command Center runs locally as your normal user, so the most important boundary is untrusted data reaching the app.

βœ… In scope, for example:

  • a repository, submodule, Git remote, or its output making the app run commands or misbehave without your review;
  • a setup bundle or settings import changing what runs automatically or reading files it shouldn't;
  • credentials or private data leaking to other local users, logs, Activity, or exports;
  • a way around command review, so something runs that you didn't approve;
  • problems in the release packages, the Arch recipe, or the CI workflows that build them.

❌ Out of scope:

  • actions that need someone already running code as your user, or with root;
  • commands you reviewed and approved yourself;
  • installer scripts from Commander Toolbox: report those to that repository.

There aren't any published security advisories