Skip to content

Security: kcemate/ratchet

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Email security@ratchetcli.com with details. Do not open public issues for security vulnerabilities.

We aim to acknowledge reports within 48 hours and triage within 5 business days.

Supported Versions

Only the latest minor version receives security patches.

Scope

  • The ratchet-run npm package
  • The Ratchet CLI binary
  • Code under src/ and bin/ in this repository

Out of scope: third-party dependencies (report upstream), demo/sandbox environments, or issues arising from misuse.

There aren't any published security advisories