If you discover a security vulnerability in AgentGit, please do not open a public issue.
Instead, report it privately via GitHub's Security Advisories for this repository. Include:
- A description of the vulnerability and its potential impact
- Steps to reproduce
- Affected version(s)
You should receive an acknowledgement within 5 business days. We'll work with you to understand and address the issue before any public disclosure.
AgentGit executes shell commands defined in repository configuration (.agentgit/config.yaml) as part of its validation gate. Treat any repository orchestrated by AgentGit as a trust boundary: only run AgentGit against repositories and configs you trust, the same way you would treat any CI configuration.
Security fixes are provided for the latest minor release on the main branch. There is no long-term support branch yet — this project is pre-1.0.