Security fixes are provided for the current release line on a best-effort basis.
| Version | Supported |
|---|---|
| 0.1.x | Yes |
| Earlier or unreleased versions | No |
Use GitHub's private vulnerability reporting for a suspected security vulnerability. Do not open a public issue until the report has been reviewed and coordinated disclosure is appropriate.
Include the affected version, operating system, installation method, impact, and the smallest reproduction you can provide. Git Buoy observes local repositories, so remove unrelated repository contents, credentials, remote URLs, usernames, and private paths from the report whenever possible.
Reports are reviewed on a best-effort basis. There is no guaranteed response or remediation time. You can expect the maintainer to acknowledge a report, assess whether it is in scope, and coordinate next steps through the private advisory when action is required.
Ordinary defects, terminal compatibility findings, and accessibility reports belong in the public issue tracker.