slice is distributed as a single command-line binary, and security fixes are
released against the latest version only. Please make sure you are on the most
recent release before reporting an issue.
| Version | Supported |
|---|---|
| latest | ✅ |
| older | ❌ |
Please report security vulnerabilities privately — do not open a public issue, as that could expose other users before a fix is available.
Use GitHub's private vulnerability reporting to reach the maintainer:
When reporting, please include as much of the following as you can:
- A description of the vulnerability and its impact.
- Steps to reproduce — ideally a minimal
sliceinvocation with the input and the expected vs. actual behavior. - The
sliceversion (slice --version), your operating system, and how you installed it.
- Acknowledgement: we aim to confirm receipt within a few days.
- Updates: we will keep you informed as we investigate and work on a fix.
- If accepted: we will prepare a fix, publish a new release, and coordinate public disclosure with you — crediting you for the report unless you prefer to stay anonymous.
- If declined: we will explain why we do not consider the report a security issue.
Thank you for helping keep slice and its users safe.