Skip to content

Security: Alqudimi/PatchSignal

Security

SECURITY.md

Security Policy

Supported versions

Only the latest release on the main branch is currently supported because PatchSignal is in its initial release line.

Reporting a vulnerability

Do not open a public issue for a suspected vulnerability. Contact the maintainer privately through the security contact shown on the GitHub profile and include a minimal reproduction, affected version, impact, and whether source content could be exposed. Please allow reasonable time for triage and coordinated disclosure.

PatchSignal is designed to analyze untrusted repositories without executing their code. Reports that demonstrate command injection, unsafe path handling, unintended network access, or secret exposure receive priority.

There aren't any published security advisories