If you discover a security vulnerability, please do not file a public Issue.
Send an email to menfre@proton.me, preferably PGP-encrypted.
We will acknowledge receipt within 48 hours and publicly credit you after the fix (let us know if you prefer to remain anonymous).
| Version | Support Status |
|---|---|
| v0.5.x | ✅ Security fixes |
| v0.4.x | ✅ Security fixes |
| ≤ v0.3.x | ❌ No longer supported |
- Waveloom never silently executes commands or modifies files — all write operations require user confirmation by default
--bypass-permissionsshould only be used in trusted CI environments- Do not commit the API Key in
settings.jsonto public repositories - Shell commands run as the current user; ensure build tools like
make,go,npmcome from trusted sources