If you discover a security vulnerability in cloudfits, please do not open a public issue. Instead, report it privately to the maintainer.
Desired way to report:
- GitHub private vulnerability reporting — go to the repository → Security tab → Report a vulnerability (recommended).
- Alternatively, open a GitHub issue
with
[SECURITY]in the title only if private reporting is not enabled.
- Affected version(s).
- Steps to reproduce.
- Impact and any suggested mitigation, if known.
- Acknowledgment of receipt: within 48 hours.
- Initial triage: within 1 week.
- We will coordinate a fix and a coordinated disclosure.
- All components under this repository (CLI, common library, TUI, web UI/docs).
Out of scope: third-party provider APIs and their pricing data (we reflect public listings and are not responsible for provider service security).