The current release line is 0.1.0-alpha. Security fixes target the newest alpha; older alpha builds should be upgraded. No stable release currently receives security support. Do not assume the CLI establishes complete effective authorization or use its output as the sole basis for an access-control decision.
For a suspected vulnerability, submit a private vulnerability report. Private reporting is enabled for this repository. Maintainers can receive reports through GitHub; a dedicated security email address and response SLA have not been established. Do not put tokens, private organization data, or exploit details in public issues.
Include the affected revision, operating system, minimal synthetic reproduction, expected security boundary, and observed behavior. Remove credentials and personal data. If a credential was exposed, revoke it with its issuer; deleting a log or issue does not revoke a token.
Maintainers should acknowledge privately, reproduce with synthetic fixtures, agree disclosure timing with the reporter, patch and add regression coverage, and publish an advisory when distribution warrants it. These are intended practices, not a guaranteed response time.
See the security model, threat model, and privacy statement. External native execution requires explicit local trust; workspace execution also requires exact local approval. It is not sandboxed; see the external provider boundary.