Security fixes are applied to the latest released installer version. Users should upgrade to the latest release before reporting an issue that may already have been addressed.
Do not disclose suspected vulnerabilities in a public GitHub issue, discussion, or pull request.
Report them privately through Cloudsmith Support. Include:
- the installer script and release version
- the operating system and architecture
- clear reproduction steps or a proof of concept
- the potential impact
- any suggested remediation
Remove API keys, tokens, credentials, private repository URLs, and other sensitive data from logs and examples. Cloudsmith will coordinate disclosure and remediation with the reporter.