| Version | Supported |
|---|---|
| latest release | ✅ |
| older releases | ❌ (please upgrade) |
Do not open a public GitHub issue for security vulnerabilities.
Please report privately via one of:
- GitHub Security Advisories — Report a vulnerability (preferred)
- Email the maintainers listed in the repository profile
Include as much of the following as you can:
- Description of the issue and its impact
- Steps to reproduce / proof of concept
- Affected version or commit
- Any suggested fix
- We acknowledge reports within 72 hours
- We aim to provide a fix or mitigation plan within 14 days for critical issues
- Credit will be given in the advisory unless you prefer to remain anonymous
GitFerry stores platform access tokens (GitHub / GitLab / Gitee / GitLink …) encrypted at rest (ENCRYPTION_KEY). Issues involving credential leakage, auth bypass, RCE, or SSRF via clone/proxy URLs are treated as critical.
Out of scope (unless they lead to the above):
- Denial of service via resource exhaustion
- Vulnerabilities in third-party dependencies without a realistic exploit path in GitFerry
- Social engineering of operators