Skip to content

Security: sQVe/grove

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest release is supported with security updates.

Reporting a Vulnerability

Do not open a public issue for security vulnerabilities.

Use GitHub's private vulnerability reporting:

  1. Go to the Security tab
  2. Click "Report a vulnerability"
  3. Provide details about the issue

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Scope

Security issues include:

  • Arbitrary code execution
  • Path traversal
  • Credential exposure
  • Command injection

Normal functionality (like deleting your own worktrees) is not a security issue.

Response

We aim to respond within 7 days and will work with you to understand and address the issue.

There aren’t any published security advisories