Skip to content

Security: fmind/dot

.github/SECURITY.md

Security Policy

Supported versions

Only the latest release is supported. Fixes land on main and ship in the next release; older tags receive no backports.

Reporting a vulnerability

Report privately through GitHub private vulnerability reporting or to contact@fmind.dev, the contact address published on fmind.dev. Include the affected version, impact, and a minimal reproduction with sensitive data removed. Do not open a public issue for an undisclosed vulnerability, and never include secrets or tokens in a report.

This is a personal project maintained on a best-effort basis; there is no response-time commitment.

Scope

In scope: install.sh, the chezmoi source tree, the dot CLI, the GitHub workflows, and the agent configurations and skills shipped here.

By design, setup runs unpinned third-party installers (mise.run, then the Grok and Antigravity vendor scripts during apply) and installs workstation tools with signature and provenance verification off (repository tools keep mise's defaults); theme files are pinned to an upstream commit and fonts to release versions, all with SHA-256 checksums. See install.sh and the trade-off stated in dot_config/mise/config.toml. Report vulnerabilities in mise, chezmoi, the agent harnesses, or any installed tool to their upstream projects.

There aren't any published security advisories