| Version | Supported |
|---|---|
| 9.x | ✅ Active support |
| 8.x | |
| < 8.0 | ❌ End of life |
Do not open a public GitHub issue for security vulnerabilities.
Instead, please report vulnerabilities privately using one of these methods:
-
GitHub Security Advisory (preferred): Use GitHub's private vulnerability reporting to submit a confidential report.
-
Email: Send details to the maintainer via the email listed in the npm package.
- Description of the vulnerability
- Steps to reproduce
- Affected versions
- Potential impact
- Suggested fix (if any)
| Action | Timeline |
|---|---|
| Acknowledgment | Within 48 hours |
| Initial assessment | Within 5 business days |
| Fix release (critical) | Within 7 days |
| Fix release (moderate) | Within 30 days |
Tribunal Kit follows these security principles:
- No network requests at runtime — The CLI operates entirely offline. The only network call is an optional npm registry version check during
init/update, which can be skipped with--skip-update-check. - No code execution from user input — CLI arguments are parsed without
eval()or shell interpolation. All subprocess spawning uses array-based arguments (never string concatenation). - No secrets stored — Tribunal Kit does not store, read, or transmit API keys, tokens, or credentials.
- Minimal dependencies — Zero production dependencies. Only
jest,eslint, andtypescriptas devDependencies. - Platform binaries are optional — The Rust core binary is distributed as optional dependencies. The CLI falls back to pure JavaScript if binaries are unavailable.
- All releases are published from CI via GitHub Actions
- Platform binaries are built in GitHub-hosted runners with pinned action versions
- The package uses
npm provenancefor verifiable supply chain attestation
We would like to thank the following security researchers for responsibly disclosing vulnerabilities:
- Michel — For identifying and responsibly disclosing a command injection vulnerability (fixed in v9.2.4).