| Channel | Description | Contact / Link |
|---|---|---|
| Private report | Preferred channel for sensitive reports. | Report a vulnerability |
| Issues | Non-sensitive problems. | Open an issue |
| Alternative contact. | security@the-white-rabbits.fr |
Please do not disclose a vulnerability publicly until it has been reviewed and fixed.
| Version | Supported |
|---|---|
1.x |
Yes |
0.1.x |
No |
Only the latest minor version of the latest major version receives fixes.
- php-dev-tools is a development tool: it runs the tools of a project (Pint, PHPStan, Rector, PHP Insights, markdownlint) with
proc_open, writesbuild/pint.jsonin the project, and its Git hooks run the Composer scripts of the project. It has no server and no user account. - It runs the commands without a shell: the arguments are not read by one. It reads the
pint.jsonof the project, and it never executes a file other than the tools and the scripts of the project. - Report any way to make it run a command, or write a file, that the project did not ask for.
- A tool that reports a wrong result, or a rule that is too strict, is not a vulnerability: open an issue.