Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Security: TortoiseGit/TortoiseGit

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Vulnerabilities in TortoiseGit can be reported using:

Vulnerabilities are expected to be discussed only using these two methods, and not in public, until the official announcement on the release date.

Examples for details to include:

  • Ideally a short description (or a script) to demonstrate an exploit.
  • The affected scenarios.
  • The name and affiliation of the security researchers who are involved in the discovery, if any.
  • Whether the vulnerability has already been disclosed.
  • How long an embargo would be required to be safe.

We prefer all communication to be in English or German.

Supported Versions

TortoiseGit only supports the most recent stable release. There are no official "Long Term Support" versions for TortoiseGit.

Based on the vulnerability, we decide how to distribute the fix, e.g. as a separate patch or as a new stable release containing either only the patch or also other fixes.

Preview versions

TortoiseGit also provides preview releases (these are not stable releases) of the current development as per TortoiseGit's master branch at the previews page on an irregular basis.

We ensure that people who run a preview release are also automatically notified for fixed versions using our automatic updater.

Note: in other projects' nomenclature these may be referred to as "nightly builds"

There aren’t any published security advisories

Morty Proxy This is a proxified and sanitized view of the page, visit original site.