The WSO2 CLI is in early development. Security reports may concern source code, dependencies, build or release workflows, exposed credentials, confidential information, unsafe examples, or weaknesses in documented security boundaries.
Do not disclose a security-sensitive concern in a public issue, discussion, or pull request.
Use GitHub's private vulnerability-reporting feature for this repository when it is available. If that feature is unavailable, contact the repository owner through a private channel before sharing technical details.
Include:
- the affected document and section;
- the nature and potential impact of the concern;
- the minimum information required to reproduce or assess it; and
- a proposed remediation, when available.
Do not include real credentials, customer data, or unnecessary private infrastructure details in the report.
Non-sensitive documentation defects may be reported through the public issue tracker.