Skip to content

Security: its-DeFine/punch-cli

Security

SECURITY.md

Security policy

Reporting a vulnerability

Do not publish vulnerabilities, invitations, credentials, session files, private keys, provider IP addresses, container identifiers, or workload content in a GitHub issue.

Use GitHub's private vulnerability reporting for this repository. Include:

  • A concise description and affected CLI version.
  • Buyer or Provider surface.
  • Reproduction steps using synthetic data.
  • Expected and observed behavior.
  • Security impact.

Do not test against another user's account, provider, workload, or capacity. Do not access customer data or attempt persistence.

Lost or exposed invitation

Do not redeem it. Contact Punch support through the private channel that delivered the invitation and request revocation and replacement.

Supported versions

Only the latest published preview release receives security fixes during the invitation-only pilot.

There aren't any published security advisories