Security fixes are made on the latest released version of rollcli. Older
versions may be fixed at maintainer discretion.
Please do not open a public issue for a suspected vulnerability. Use GitHub private vulnerability reporting for this repository when it is available. If it is not enabled, contact the repository owner privately through GitHub and include:
- a clear description of the issue and its potential impact;
- steps to reproduce it, preferably with a minimal example;
- affected versions and environment details; and
- any proposed mitigation, if known.
Maintainers should acknowledge reports promptly, investigate privately, and coordinate a fix and release before public disclosure. Enable GitHub's private vulnerability reporting in the repository security settings to make this path available to reporters.