Skip to content

Security: stack-sh/cli

SECURITY.md

Security policy

Supported versions

Stack CLI 0.4.0 is the supported stable binary release. Before 1.0, only the latest stable release receives release support; main is an unreleased development revision. Download supported binaries and their verification material from the v0.4.0 GitHub Release.

Reporting a vulnerability

Do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting for stack-sh/cli so maintainers can investigate before disclosure.

Include the affected revision, reproduction steps, impact, and any suggested mitigation. Do not include real credentials, customer data, or other people's private information in the report.

The project will acknowledge a report, assess its scope, and coordinate remediation and disclosure through the private report. This policy does not promise a bug bounty or a fixed response deadline.

There aren't any published security advisories