Skip to content

Security: omar16100/atlassian-cli

Security

SECURITY.md

Security Policy

atlassian-cli is an independent open-source project. It is not affiliated with, endorsed by, sponsored by, or maintained by Atlassian.

Scope

atlassian-cli runs entirely on the user's own machine. API tokens are stored locally with AES-256-GCM encryption, in credentials.enc inside the config directory (~/.config/atlassian-cli by default; see the README for how that is chosen). On Unix the directory is 0700 and the files 0600. Windows has no equivalent mode, and relies on %LOCALAPPDATA% being user-only. The project and the atlassian-cli.pages.dev website never receive, transmit, or process user Atlassian credentials.

Supported versions

Security fixes are applied to the latest released version on crates.io. Please upgrade before reporting an issue to confirm it still reproduces.

Reporting a vulnerability

Please report suspected vulnerabilities privately — do not open a public issue for security problems.

Please include: affected version, reproduction steps, and impact. We aim to acknowledge within 7 days and to provide a remediation timeline after triage.

Disclosure

Coordinated disclosure is preferred. We will credit reporters in the release notes unless anonymity is requested.

There aren't any published security advisories