Skip to content

Security: Lantharos/Argent

Security

SECURITY.md

Security Policy

If you believe you have found a security vulnerability in Argent, please avoid posting full exploit details in a public issue right away.

Reporting

  • Prefer GitHub's private vulnerability reporting flow.
  • If that is not available, use the most direct private maintainer contact method listed on the repository or profile.
  • If private reporting is not possible, keep any initial public report minimal and avoid sharing secrets, exploit steps, or sensitive system details.

What To Include

Please include:

  • a short description of the issue
  • affected versions or commit range if known
  • reproduction steps
  • impact
  • any suggested mitigation

Scope Notes

Argent is pre-release software. Reports are still very helpful, especially around:

  • Electron or webview boundary issues
  • filesystem access issues
  • terminal execution issues
  • secret storage handling
  • command injection or path traversal risks

Response Expectations

Security reports are appreciated, but there is no guaranteed response SLA yet.

There aren't any published security advisories