Skip to content

Security: jonpecson/qa-captain

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in QA Captain, please report it responsibly:

  1. Do not open a public issue
  2. Email the maintainer or open a private security advisory on GitHub
  3. Include steps to reproduce, impact assessment, and any suggested fixes

We will acknowledge receipt within 48 hours and provide a timeline for resolution.

Scope

QA Captain is a local-first CLI tool. It:

  • Reads git repository data locally
  • Writes files to the local .qa-captain/ directory
  • Does not transmit data to external services
  • Does not execute arbitrary code from diffs

Supported Versions

Version Supported
0.1.x Yes

There aren't any published security advisories