If you discover a security vulnerability in Carrot, please report it responsibly.
Do not open a public GitHub issue for security vulnerabilities.
Instead, please email: security@carrot.dev
Include:
- A description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
We will acknowledge your report within 48 hours and aim to provide a fix or mitigation within 7 days for critical issues.
This policy covers:
- The Carrot terminal emulator (
carrot-app) - The Inazuma framework (
inazuma) - Shell integration hooks (
carrot-shell) - PTY handling and terminal emulation (
carrot-terminal,carrot-term)
As Carrot is in active development and has not yet reached a stable release, security fixes are applied to the main branch.