Security fixes target the latest release and the default branch.
| Version | Supported |
|---|---|
| Latest release | Yes |
| Default branch | Yes |
| Older releases | No |
Do not open a public issue for a suspected vulnerability.
Use GitHub private vulnerability reporting. Include:
- affected release or commit;
- minimal synthetic or redacted reproduction;
- expected security impact;
- suggested mitigation, when known.
Do not include credentials, raw hook payloads, file contents, prompts, transcripts, private URLs, personal data, or unrelated diagnostics.
These are response targets, not disclosure deadlines.
| Severity | Acknowledge | Triage | Fix or mitigation |
|---|---|---|---|
| Critical | 2 business days | 5 business days | As soon as practical |
| High | 3 business days | 7 business days | Next patch release |
| Medium | 5 business days | 15 business days | Planned patch |
| Low | 10 business days | 30 business days | Planned maintenance |
Source code, workflows, generated instructions, release assets, hook installation, local checkpoint storage, Git object retention, and attribution notes are in scope.
The production binary makes no background network connections. Telemetry,
silent update checks, remote lookups, and cloud synchronization are forbidden.
Network access exists only in git-byline update and
git-byline version --check: both run curl through internal/runner against
the pinned GitHub release repository over HTTPS, and the update download must
still match checksums.txt before the swap. The managed pre-push hook may
invoke Git to fetch attribution notes from the push remote and publish them
there unless installation used --local-notes. Any other network behavior
is a security defect.
Checkpoint metadata and notes must not contain raw hook input, prompts, transcripts, environment dumps, authorization data, or file content. Snapshot blobs contain local file content and must stay protected from unintended ref or artifact publication.
Third-party platforms and agent products remain outside project control unless the defect is in git-byline integration behavior.
Please allow time to investigate and release a fix before public disclosure. Security advisories credit reporters who request credit. Details stay private until coordinated disclosure is safe.