Only the latest release receives security fixes. cprof has no LTS branches;
update with brew upgrade cprof or by re-running the installer.
Report vulnerabilities privately through GitHub: Security → Report a vulnerability.
Do not open a public issue for anything security-sensitive. cprof manages
Claude account credentials and keychain entries, so treat anything touching
scripts/lib/auth.sh, profile directories, or the installer as sensitive.
- Acknowledgement within 7 days.
- Assessment and a fix or mitigation plan within 30 days of acknowledgement.
- Coordinated disclosure: fixed vulnerabilities are published as GitHub Security Advisories on this repository once a patched release is out, normally within 90 days of the report.
In scope: the cprof CLI, its library scripts, the shell hooks and
statusline segment, and install.sh. Out of scope: Claude Code itself,
Homebrew, and vulnerabilities requiring an already-compromised local account.
The threat model and mitigations are documented in docs/security-assessment.md.