Whippletree

Security policy

Reporting

Report vulnerabilities privately through GitHub's advisory form: https://github.com/larstonder/whippletree/security/advisories/new

Please do not open a public issue for anything exploitable. This is a single-maintainer project, so expect an acknowledgement within a few days rather than a few hours.

Supported versions

Pre-1.0. Only the latest release gets fixes.

What is in scope

Whippletree compiles a bundle's declared contract into a harness's native hook configuration, and whippletree-hook executes that bundle's handlers at runtime. The interesting boundary is a bundle you did not author.

In scope:

Out of scope:

Verifying a release

Releases are signed with cosign keyless and carry SLSA build provenance. The exact verification commands are in each release's notes.

Source: SECURITY.md