Skip to content

Security: trippwill/tuck

SECURITY.md

Security

Reporting a vulnerability

Please report security issues privately when possible. Use GitHub's private vulnerability reporting or repository security advisory flow if it is available.

If private reporting is not available, open a minimal public issue asking for a secure contact path. Do not include exploit details, secrets, or sensitive local paths in a public issue.

Scope

tuck manages local files and symlinks, including optional root-context targets. Reports involving unsafe writes, privilege-boundary mistakes, state corruption, or path traversal are especially useful.

There aren't any published security advisories