| Version | Supported |
|---|---|
main / latest release (1.x) |
Yes |
| Older tags | No — please upgrade |
Security fixes land on main and ship in the next npm release of @thisux/pi-worktree.
Do not open a public GitHub issue for security-sensitive findings.
Email hello@thisux.com with subject:
[security] thisuxhq/pi-worktree
Include:
- Description of the issue and potential impact
- Steps to reproduce (or a proof of concept)
- Affected version / commit if known
- Any suggested fix
We will acknowledge within a few business days and work with you on a fix and disclosure timeline.
This package is a Pi extension that runs git / gh via the coding agent. Reports that matter most:
- Unsafe command construction or argument injection
- Worktree remove/force paths that destroy data without confirmation
- Path traversal outside expected worktree layout
- Supply-chain issues in published tarballs