Skip to content

Security: ashutoshpw/wise-cli

Security

SECURITY.md

Security Policy

Reporting bugs

Report reproducible bugs through the GitHub issue tracker. Use the bug report form and include the CLI version, operating system, command, expected behavior, actual behavior, and minimal reproduction steps.

Before submitting logs or configuration, remove API tokens, authorization headers, profile IDs, account IDs, transfer IDs, and other financial or personal data. Never attach .env.local or paste an active Wise API token into an issue.

Reporting security vulnerabilities

Do not disclose a security vulnerability, exposed credential, or exploit in a public GitHub issue. Report it privately through GitHub Security Advisories.

Include a clear description, affected version or commit, reproduction steps, impact, and any suggested remediation. Please allow the maintainers a reasonable opportunity to investigate and release a fix before public disclosure.

If a Wise credential has been exposed, revoke it immediately in Wise, replace it anywhere it is used, and remove it from affected files and Git history.

Supported versions

Security fixes target the latest release and the current main branch. Older versions may not receive security updates.

There aren't any published security advisories