Skip to content

Security: pushmanhq/pushman-cli

SECURITY.md

Security Policy

Supported versions

Pushman CLI is currently in private beta and has no supported public release line. After the first release, security fixes will target the latest published version.

Report a vulnerability

Use GitHub private vulnerability reporting to report a suspected vulnerability. Do not open a public issue, discussion, or pull request.

Include a concise description, affected version or commit, reproduction steps, impact, and any suggested mitigation. Remove all real credentials, message contents, private hostnames, and personal data. You can expect an initial acknowledgement within seven days. We will coordinate remediation and disclosure through the private advisory.

Never submit a real PUSHMAN_TOKEN, account CLI credential, OAuth assertion, signing material, production configuration, or unredacted diagnostic output.

Scope

This policy covers code in this repository and its release artifacts. Hosted-service and iPhone-app security reports may still be submitted through the same private advisory; the maintainer will route them to the appropriate private project.

There aren't any published security advisories