Please do not report security vulnerabilities through public GitHub issues.
Instead, report them privately using GitHub's private vulnerability reporting.
Please include as much of the following as you can:
- A description of the vulnerability and its potential impact
- Steps to reproduce, including a minimal example if possible
- The
satchelversion affected (satchel --version)
You should expect an initial response within a few days. We'll work with you to understand and validate the issue, and to agree on a disclosure timeline once a fix is available.
satchel is a CLI tool distributed as tagged releases. Security fixes are
made against the latest release; there is no separate long-term support
branch. Please upgrade to the latest version before reporting an issue to
confirm it is still present.