yalethom.as/txtop

Security policy

Supported versions

Security fixes are provided for the latest 1.x release. Upgrade to the newest published version before reporting an issue that may already be resolved.

Report a vulnerability

Use GitHub’s private vulnerability reporting flow on the txtop Security page. Do not include credentials, local usage logs, debug bundles, or other sensitive data in a public issue.

If private reporting is unavailable, open a public issue containing only a request for a private contact channel. Do not describe the vulnerability until a maintainer responds privately.

Sensitive data boundaries

txtop can read API credentials, local coding-agent logs, and provider usage data. Debug-bundle redaction is best effort. Always inspect generated artifacts before sharing them, and revoke any credential that may have been exposed.