Only the latest release is supported. Fixes land on main and ship in the next release; older tags receive no backports.
Report privately through GitHub private vulnerability reporting or to contact@fmind.dev, the contact address published on fmind.dev. Include the affected version, impact, and a minimal reproduction with sensitive data removed. Do not open a public issue for an undisclosed vulnerability, and never include secrets or tokens in a report.
This is a personal project maintained on a best-effort basis; there is no response-time commitment.
In scope: install.sh, the chezmoi source tree, the dot CLI, the GitHub workflows, and the agent configurations and skills shipped here.
By design, setup runs unpinned third-party installers (mise.run, then the Grok and Antigravity vendor scripts during apply) and installs workstation tools with signature and provenance verification off (repository tools keep mise's defaults); theme files are pinned to an upstream commit and fonts to release versions, all with SHA-256 checksums. See install.sh and the trade-off stated in dot_config/mise/config.toml. Report vulnerabilities in mise, chezmoi, the agent harnesses, or any installed tool to their upstream projects.