Skip to content

Security: ryanlewis/things-cli

SECURITY.md

Security Policy

Supported versions

Only the latest release is supported with security fixes.

Reporting a vulnerability

Please report vulnerabilities privately via GitHub Security Advisories — do not open a public issue. You should get a response within a week.

Verifying releases

Release artifacts are checksummed (checksums.txt, verified automatically by install.sh) and carry build provenance attestations:

gh attestation verify things_<version>_darwin_arm64.tar.gz -R ryanlewis/things-cli

There aren't any published security advisories