| Version | Supported |
|---|---|
| 1.5.x | ✅ |
| < 1.5 | ❌ |
If you discover a security vulnerability, please report it responsibly:
- Do NOT open a public issue.
- Email security@moussamokhtari.com with details of the vulnerability.
- Include steps to reproduce, potential impact, and any suggested fixes.
We will acknowledge receipt within 48 hours and aim to provide a fix within 7 days for critical issues.
- API keys are stored locally in
~/.aicommit/configand never transmitted except to the configured AI provider. - No telemetry or analytics data is collected.
- All AI provider communication uses HTTPS.
- GitHub Actions workflows use pinned SHA hashes to prevent supply-chain attacks.