Skip to content

Security: ChanTsune/slice

SECURITY.md

Security Policy

Supported Versions

slice is distributed as a single command-line binary, and security fixes are released against the latest version only. Please make sure you are on the most recent release before reporting an issue.

Version Supported
latest
older

Reporting a Vulnerability

Please report security vulnerabilities privately — do not open a public issue, as that could expose other users before a fix is available.

Use GitHub's private vulnerability reporting to reach the maintainer:

Report a vulnerability »

When reporting, please include as much of the following as you can:

  • A description of the vulnerability and its impact.
  • Steps to reproduce — ideally a minimal slice invocation with the input and the expected vs. actual behavior.
  • The slice version (slice --version), your operating system, and how you installed it.

What to expect

  • Acknowledgement: we aim to confirm receipt within a few days.
  • Updates: we will keep you informed as we investigate and work on a fix.
  • If accepted: we will prepare a fix, publish a new release, and coordinate public disclosure with you — crediting you for the report unless you prefer to stay anonymous.
  • If declined: we will explain why we do not consider the report a security issue.

Thank you for helping keep slice and its users safe.

There aren't any published security advisories