| Version | Supported |
|---|---|
| 1.x.x | Yes |
DO NOT open a public GitHub issue for security vulnerabilities.
Please report security vulnerabilities via one of the following channels:
- Email: security@elnora.ai
- GitHub Security Advisories: Report a vulnerability
Include as much detail as possible:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Acknowledgement: Within 48 hours of report
- Initial assessment: Within 5 business days
- Fix and disclosure: Within 90 days of report
We follow a 90-day disclosure timeline. We ask that you:
- Allow us reasonable time to fix the issue before public disclosure
- Do not access or modify other users' data
- Do not perform actions that could negatively impact other users
- Act in good faith to avoid privacy violations, data destruction, and service disruption
In scope:
- The
elnora-linearCLI and plugin code in this repository - Configuration handling (
references/*.json, env var resolution, API-key storage) - Signal sources implemented in this repo (currently only
external_command; the other source types inschemas/signal-sources.jsonare declared but not yet implemented)
Out of scope:
- Third-party dependencies (please report to their respective maintainers)
- The Linear API itself (report to Linear)
- User-configured
external_commandentries — those execute commands the user has chosen to trust - Social engineering attacks against Elnora staff
- Denial of service attacks
- Issues in services not operated by Elnora
- Never commit API keys or tokens to version control
- The plugin saves your Linear API key to
~/.config/elnora-linear/.envwith mode0600by default — verify this if you suspect tampering - Rotate your Linear API key periodically via Linear's account settings
- When configuring
external_commandsignal sources, only point at trusted local binaries