ccmux ships as a single rolling release. Only the latest published version on the releases page receives security fixes. If you are on an older version, please upgrade before reporting.
| Version | Supported |
|---|---|
| Latest release | ✅ |
| Older releases | ❌ |
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Report vulnerabilities privately through GitHub's private vulnerability reporting:
- Go to the Security tab of the repository.
- Click Report a vulnerability (or use this direct link).
- Fill in the advisory with as much detail as you can.
If the advisory form is unavailable for any reason, email epilande@gmail.com instead.
Please include:
- A description of the vulnerability and its impact.
- Steps to reproduce, or a proof of concept.
- The affected
ccmux --version, your OS, and your tmux version (tmux -V). - Any relevant configuration (installed hooks, custom agents, non-default config).
- We aim to acknowledge new reports within a few days.
- We will keep you updated on our progress as we investigate and work on a fix.
- Once a fix is released, we are happy to credit you in the advisory unless you prefer to remain anonymous.
Thank you for helping keep ccmux and its users safe.