Stack CLI is pre-release. Security fixes are applied to the latest revision on main; no released binary version is currently supported.
Do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting for stack-sh/cli so maintainers can investigate before disclosure.
Include the affected revision, reproduction steps, impact, and any suggested mitigation. Do not include real credentials, customer data, or other people's private information in the report.
The project will acknowledge a report, assess its scope, and coordinate remediation and disclosure through the private report. This policy does not promise a bug bounty or a fixed response deadline.