English · فارسی
| Version | Supported |
|---|---|
| 2.0.x (current) | Yes |
| 1.x legacy scripts | No — migrate to v2 package |
Do not open a public GitHub issue with exploit details, tokens, FTP passwords, or customer data.
- Use GitHub private vulnerability reporting if enabled, or email the maintainer through a private channel (see SUPPORT.md).
- Include: version, affected command (
ship,ftp sync, …), impact, and minimal reproduction without real secrets. - If a token leaked, say so immediately so it can be rotated on Chabokan Hub.
We aim to acknowledge reports within 72 hours and provide a fix or mitigation timeline when valid.
In scope
- Credential leakage via CLI output or logs
- FTP orphan purge or
--cleandeleting preserved paths incorrectly - False skip/verify allowing stale remote content while reporting success
- Path traversal or unsafe file operations in staging/upload
Out of scope
- Vulnerabilities in Chabokan Hub/FTP infrastructure itself
- Issues requiring attacker access to your already-compromised
.env.chabokan - Denial of service against third-party Chabokan APIs
credentials fetchredacts secrets unless--show-secrets.env.chabokanis gitignored — use.env.chabokan.examplefor templates only- Live tests must not target production customer projects