| Version | Supported |
|---|---|
| 0.x (latest) | ✅ |
Open a GitHub Security Advisory or email the maintainer directly. Do not file a public issue for security vulnerabilities.
You should receive a response within 72 hours. If the issue is confirmed, a fix will be prepared and released as a patch version.
- API key or token leaks through pm-agent output or logs.
- Unauthorized file system or git operations via action approval bypass.
- SQL injection through stored history, notes, or decision content.
Out of scope: vulnerabilities in the LLM provider endpoint, OpenAI library issues, or OS-level sandboxing.