Skip to content

Security: DeliriumPulse/homebrew-codetruss

SECURITY.md

Security policy

Please do not disclose a suspected vulnerability in a public issue.

Report security concerns through GitHub's private vulnerability reporting for DeliriumPulse/codetruss-cli. Include the affected formula or CLI version, operating system, Homebrew version, reproduction steps, and impact. Do not include provider keys, CodeTruss tokens, receipt signing keys, repository secrets, or proprietary source code.

For an archive-integrity concern, include the release URL, observed SHA-256, and expected SHA-256. The current formula must never be changed to accept a mutable or unchecksummed download.

There aren't any published security advisories