Please report suspected vulnerabilities privately via GitHub's security advisory flow: Report a vulnerability. Do not open a public issue for security reports.
You can expect an initial response within a few business days. Please include
a description, reproduction steps, and the affected version (bronto --version).
Only the latest release receives security fixes. Update with your package manager or from the releases page.
| Version | Supported |
|---|---|
| latest release | yes |
| older releases | no |
Release checksums are signed with cosign (keyless):
cosign verify-blob \
--certificate checksums.txt.pem \
--signature checksums.txt.sig \
--certificate-identity-regexp 'github.com/bronto-community/bronto-cli' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
checksums.txt
sha256sum --check --ignore-missing checksums.txtRelease archives and packages also carry signed SLSA build provenance. Verify that an artifact was built by this repo's release workflow with:
gh attestation verify bronto_<version>_<os>_<arch>.tar.gz --repo bronto-community/bronto-cliSPDX SBOMs for every archive are attached to each release; container images on ghcr.io carry provenance and SBOM attestations.
brontostores API keys in the OS keychain where available (file fallback with restrictive permissions otherwise); it never transmits keys anywhere except the configured Bronto API host.- The plugin mechanism (
bronto-<name>on PATH) executes local binaries by design; treat plugin installation with the same care as installing any executable.