Do not report security vulnerabilities through public GitHub issues.
Instead, please report them via:
- GitHub Security Advisory: Report a vulnerability
Updates will be provided through the advisory thread as triage proceeds.
- Description of the vulnerability
- Steps to reproduce
- Affected versions
- Potential impact
- Suggested fix (if you have one)
The following are in scope:
- Code execution vulnerabilities in the must CLI
- Path traversal or arbitrary file access
- Supply chain issues in dependency handling
- Plugin sandbox escapes
The following are out of scope:
- Denial of service via large inputs
- Issues in dependencies (report upstream)
- Social engineering attacks
| Version | Supported |
|---|---|
| 0.2.x | Yes |
| < 0.2 | No |
When a vulnerability is reported:
- We will confirm the issue and determine affected versions
- We will patch the issue and release a new version
- We will publish a security advisory on GitHub
- We will credit the reporter (unless they prefer to remain anonymous)