Skip to content

Security: lettermint/lettermint-cli

SECURITY.md

Security reports

Use the private vulnerability reporting form in this repository's GitHub Security tab. Do not put credentials, private messages, or working access tokens in a public issue. If private reporting is not enabled, use the support channel on the official Lettermint website to request a private reporting channel.

Include the affected CLI version, operating system, steps to reproduce, and expected access boundary. Use test accounts and synthetic email. Keep email and webhook content separate from agent instructions.

Release signing keys belong only in the protected release environment. A release must fail when a required signing key is absent.

There aren't any published security advisories