| Version | Supported |
|---|---|
| latest | ✅ |
If you discover a security vulnerability in autopass, please report it responsibly:
- Do NOT open a public GitHub issue
- Use GitHub Security Advisories to report privately
- Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Acknowledgment: Within 48 hours
- Initial assessment: Within 7 days
- Fix release: Within 30 days for critical issues
Security issues we care about:
- Secret leakage (decrypted secrets exposed in memory/logs/disk)
- Encryption weaknesses (key derivation, AES-GCM usage)
- PTY escape / command injection
- Dependency vulnerabilities
Out of scope:
- Attacks requiring physical access to an unlocked machine
- Social engineering