Skip to content

Security: TheYoungChen/Chuchen-Terminal

Security

SECURITY.md

Security Policy

Supported Versions

Chuchen-Terminal is currently in MVP / preview status. Security fixes are applied to the main development line until stable release channels are established.

Reporting a Vulnerability

Please do not publish vulnerabilities, secrets, tokens, private logs, or real provider credentials in public issues.

When reporting a security issue, include:

  • affected version or commit,
  • operating system,
  • clear reproduction steps,
  • expected and actual behavior,
  • sanitized logs or screenshots.

Sensitive Data Guidelines

Do not commit or attach:

  • API keys, provider tokens, session tokens, or passwords,
  • real local workspace paths,
  • private repository names,
  • terminal logs containing company or account data,
  • screenshots showing private files, commands, or credentials.

Local-First Data

Chuchen-Terminal is designed as a local desktop application. Users are responsible for protecting local workspace data, provider credentials, and terminal history on their own machines.

There aren't any published security advisories