Security updates are provided for the latest stable version on the main branch.
| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0 | ❌ |
We take security seriously in NxtGit. If you discover a security vulnerability, please do not open a public GitHub issue.
Use the Private vulnerability reporting feature on GitHub to report vulnerabilities confidentially.
Alternatively, you can contact the maintainer directly via GitHub.
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- You will receive an acknowledgment within 48 hours
- We aim to release a patch within 7 days for critical issues
- You will be credited in the security advisory (unless you prefer anonymity)
This policy applies to:
- The NxtGit desktop application (Tauri + TypeScript)
- API token handling (GitHub, GitHub Copilot, OpenRouter, Anthropic, OpenAI, Ollama, Moonshot, Kilocode, MiniMax)
- Any secrets stored via
@tauri-apps/plugin-store
- Vulnerabilities in third-party dependencies (please report those upstream)
- Issues related to user misconfiguration