Security policy

August 1, 2026 ยท View on GitHub

Reporting a vulnerability

Please do not disclose a suspected vulnerability in a public issue.

Use GitHub's private vulnerability reporting for this repository when available. Include the affected version or commit, reproduction steps, impact, and any suggested mitigation. If private reporting is unavailable, contact the maintainer through the email address on their GitHub profile and avoid including sensitive details in the subject line.

You should receive an acknowledgement within seven days. Confirmed issues will be prioritized according to impact and fixed releases will credit reporters who want attribution.

Scope

Security-sensitive areas include command argument handling, repository path handling, external editor and difftool invocation, GitHub CLI integration, and destructive-operation confirmations.