To report a security vulnerability in this repository, please email security@warp.dev.
Do not open a public GitHub issue for security vulnerabilities. Responsible disclosure gives us time to fix the issue before it is publicly known.
Please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce or a proof-of-concept
- Any suggested mitigations if known
We will acknowledge receipt within 2 business days and aim to resolve confirmed vulnerabilities within 90 days.
This is a reference implementation. If you find a vulnerability in the pattern or configuration guidance (e.g. an unsafe shell command, a credential-handling flaw, or an injection risk in the SQL templates), please report it.
Issues with third-party integrations (Notion, BigQuery, Slack, Metabase, Sanity) should be reported directly to those vendors.