Security fixes are made against the latest release line and main.
| Version | Supported |
|---|---|
| 0.2.x | Yes |
| 0.1.x | No |
Do not disclose vulnerabilities or exploit details in a public issue.
Use GitHub's private vulnerability reporting form:
https://github.com/amitray007/ccstack/security/advisories/new
If that form is not available, open a minimal issue asking the maintainers to establish a private reporting channel. Do not include technical details, affected paths, secrets, or names in that issue.
Include the following in the private report when possible:
- the affected ccstack version and operating system;
- the installation method;
- the configuration scope and files involved;
- clear reproduction steps or a minimal fixture;
- the impact and any known mitigations;
- whether the issue is already public.
The most sensitive areas include path confinement, scope separation, secret handling, command execution, local HTTP exposure, and any mutation that can reach outside the selected Claude Code configuration root.
Maintainers will acknowledge the report, assess severity and affected versions, coordinate a fix, and credit reporters who want attribution. Please allow time for a patched release before public disclosure.