The promptargs maintainers take the security of this project seriously. Thank you for helping keep promptargs and its users safe by disclosing vulnerabilities responsibly.
Please do not report security vulnerabilities through public GitHub issues, pull requests, or discussions. Public reports expose users to the very weakness being reported before a fix is available.
Instead, use private vulnerability reporting:
- Go to the repository's Security tab.
- Click Report a vulnerability (GitHub's private security advisory flow).
- Provide a description of the issue and how to reproduce it.
If private reporting is unavailable to you for any reason, contact a repository maintainer directly rather than opening a public issue.
Please include, as much as you can:
- The affected component, version, and branch.
- A description of the vulnerability and its potential impact.
- Step-by-step instructions to reproduce it.
- Any proof-of-concept, logs, or configuration that help us confirm it.
- Acknowledgement: we aim to acknowledge your report within 5 business days.
- Assessment: we will investigate, confirm the issue, and keep you informed of our progress.
- Fix and disclosure: we will work on a fix and coordinate a disclosure timeline with you. We ask that you give us a reasonable opportunity to remediate before any public disclosure.
- Credit: with your permission, we are happy to credit you for the report.
Reports about the code in this repository are in scope. promptargs is a template argument substitution library that reads GITHUB_TOKEN for auto-detection and renders user templates, so security issues in the tool itself, its dependencies, and their integration are all relevant. When in doubt, report it privately and let us triage — we would rather hear about a non-issue than miss a real one.
Security updates are provided for the latest major version of promptargs.
Thank you for contributing to the security of promptargs.