- Notifications
You must be signed in to change notification settings - Fork842
Security: jj-vcs/jj
Security
SECURITY.md
To report a security issue, please use the "Report a vulnerability" button onGitHub's Security tab forjj's main repo, underAdvisories.
Our vulnerability management team will respond within 3 working days of yourreport. If the issue is confirmed as a vulnerability, we will open a SecurityAdvisory. This project follows a 90 day disclosure timeline.
Feel free to email Jujutsu VCS Security atjj-security@googlegroups.com if youhave questions.
- SHA-1 collisions are not detectedGHSA-794x-2rpg-rfgr published
Apr 5, 2025 bymartinvonzModerate - Remote branch name injectionGHSA-gg38-mhjq-j4mp published
Feb 7, 2025 bymartinvonzLow - Path traversal via crafted Git repositoriesGHSA-88h5-6w7m-5w56 published
Nov 6, 2024 bymartinvonzCritical
Learn more about advisories related tojj-vcs/jj in theGitHub Advisory Database