Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
63 changes: 42 additions & 21 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -1,39 +1,60 @@
# Security Policy

## Supported versions
## Reporting a Vulnerability

Only the latest release receives security updates.
**Do not open a public GitHub issue for a security vulnerability.**

## Reporting a vulnerability
Report vulnerabilities privately to **<security@jordannewell.com>**.
(Placeholder address — Jordan will replace with a dedicated security inbox.)

Email **security@jordannewell.com** with:
If you have a PGP key, encrypt the report. The fingerprint of the project's
reporting key will be published here once Jordan generates it:

- A description of the issue and its impact
- Reproduction steps (a minimal example is ideal)
- Affected version — run `temporal-git --version`
```
PGP fingerprint: TBD (to be published)
PGP public key: TBD (to be published)
```

**Do not open a public GitHub issue** for security reports.
Until the PGP key is published, plaintext email is fine — but please prefer
it over GitHub issues either way.

## Response timeline
Please include, where possible:

- **Acknowledgment:** within 72 hours
- **Initial assessment:** within 5 business days
- **Fix or mitigation:** target 30 days for high-severity issues
- A description of the issue and its impact.
- The smallest reproducer you can manage (a failing test is ideal).
- Affected versions (or the commit SHA you tested against).
- Any mitigations you've already tried.

Please refrain from public disclosure until a fix has been published, to
protect downstream users. Reporters will be credited in the release notes
unless they prefer otherwise.
## Response SLA

- **Acknowledgement:** within **48 hours** (typically same business day).
- **Initial assessment + severity rating:** within **5 business days**.
- **Fix or mitigation timeline** depends on severity:
- *Critical* (RCE, key compromise, auth bypass): patch or mitigation
within 7 days of confirmation; coordinated disclosure afterwards.
- *High*: patch within 30 days.
- *Medium / Low:* next minor release.

We will keep you informed at each step and credit you in the release notes
unless you'd prefer to remain anonymous.

## Scope

**In scope:**

- The CLI itself (`temporal-git` and its subcommands)
- The git-bisect automation logic
- The VS Code extension code
- The `temporal-git` tooling: history rewriting, snapshot, and restore logic.
- Anything that could corrupt repository history or leak commit content.

**Out of scope:**

- git itself — report upstream
- VS Code — report to Microsoft
- Dependencies — report upstream
- Vulnerabilities in third-party dependencies. Report those upstream.
- Attacks requiring a compromised maintainer, a compromised signing key, or
physical access to the reporter's machine.
- Reports from automated scanners without a working reproducer.

## Disclosure policy

We follow **coordinated disclosure**. Once a fix is available we'll publish a
GitHub Security Advisory, request a CVE if appropriate, cut a patch release,
and credit the reporter in the changelog. We will not publish details of
unpatched critical issues.
Loading