| Version | Supported |
|---|---|
| 1.0.x | ✅ |
If you discover a security vulnerability, please report it responsibly.
Do NOT open a public issue for security vulnerabilities.
Instead, please email: samann1389@gmail.com
Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Uses SSH keys only (no passwords or tokens)
- Never stores credentials in files
- Validates SSH connection before push
- Does not collect personal information beyond system info
- IP address is optional (can be disabled)
- All data stays in your repository
- Scripts require appropriate permissions
- Log files are created with restrictive permissions
- Configuration file should not contain secrets
- Uses HTTPS for public IP detection
- SSH for Git operations
- No outbound connections except to GitHub
- Keep your SSH keys secure
- Use a dedicated GitHub account if needed
- Review logs regularly
- Update the tool regularly
- Use strong SSH key passphrase
For security concerns, contact: samann1389@gmail.com