Skip to content

Security: itscloud0/readme-command-check

Security

SECURITY.md

Security Policy

readme-command-check inspects documentation and can optionally execute commands when --run is passed.

Supported Versions

Version Supported
0.1.x Yes

Reporting a Vulnerability

Open a GitHub security advisory or a private issue with:

  • the README snippet that triggers the problem,
  • the command used,
  • expected behavior,
  • actual behavior.

Execution Safety

By default, the tool does not run README commands. Static checks flag privileged commands, remote shell pipes, destructive commands, package publishing, force pushes, and placeholder values.

Only use --run on trusted repositories.

There aren't any published security advisories