Skip to content

Security: namoidhq/namoid-cli

Security

SECURITY.md

Security policy

NamoID is an identity platform, so security reports must be handled privately.

Reporting a vulnerability

Email security@namoid.in. Do not open a public GitHub issue.

Please include the affected CLI version, operating system, reproduction steps, impact, and an optional suggested fix. Remove all real credentials and personal data from reports and logs. We aim to acknowledge reports within 48 hours and provide a triage decision within five business days.

Relevant findings

  • Credential or environment-value disclosure
  • Plugin release verification or installation bypasses
  • Unsafe command execution or path handling
  • Authentication, authorization, or MCP setup weaknesses caused by the CLI
  • Dependency or supply-chain vulnerabilities that affect shipped behavior

Safe harbor

If you act in good faith, avoid service disruption and unnecessary data access, and allow reasonable time for remediation before disclosure, NamoID will not pursue legal action for your security research.

There aren't any published security advisories