| Version | Supported |
|---|---|
| latest | ✅ |
We take the security of Twitter CLI seriously. If you believe you've found a security vulnerability, please follow these steps:
- Do NOT disclose the vulnerability publicly (no GitHub issues, forums posts, social media, etc.).
- Email the details to: security@stanleymasinde.com
- Include a detailed description of the vulnerability
- Steps to reproduce the issue
- Potential impact
- Any suggestions for remediation
- Acknowledgment: We'll acknowledge your email within 48 hours.
- Verification: Our team will verify the vulnerability and determine its impact.
- Fix Development: If confirmed, we'll develop a fix.
- Public Disclosure: Vulnerabilities will only be disclosed publicly after a fix has been released.
When using Twitter CLI:
- Keep your tokens secure: Never share your Twitter API credentials.
- Update regularly: Always use the latest version of the CLI.
- Review permissions: Ensure your Twitter app has only the permissions it needs.
This project depends on various third-party libraries. We strive to:
- Keep dependencies up-to-date
- Monitor security advisories for dependencies
- Address security issues promptly
Thank you for helping keep Twitter CLI secure!