Security policy
Supported versions
Security fixes are provided for the latest 1.x release. Upgrade to the newest published version before reporting an issue that may already be resolved.
Report a vulnerability
Use GitHub’s private vulnerability reporting flow on the txtop Security page. Do not include credentials, local usage logs, debug bundles, or other sensitive data in a public issue.
If private reporting is unavailable, open a public issue containing only a request for a private contact channel. Do not describe the vulnerability until a maintainer responds privately.
Sensitive data boundaries
txtop can read API credentials, local coding-agent logs, and provider usage data. Debug-bundle redaction is best effort. Always inspect generated artifacts before sharing them, and revoke any credential that may have been exposed.