Security fixes are applied to the latest release on the default branch.
Use GitHub's private vulnerability reporting feature:
- Open the repository's Security tab.
- Select Report a vulnerability.
- Include the affected version, reproduction steps, impact, and any proposed mitigation.
Do not publish credentials, private server addresses, servers.json, private
keys, or screenshots containing infrastructure details.
- The application executes system OpenSSH (
ssh.exeon Windows and/usr/bin/sshon macOS). - Remote forwarded ports bind to
127.0.0.1. - Saved passwords are protected with Windows DPAPI or stored in the current user's macOS login Keychain.
- Automatic remote proxy setup only edits its marked block and creates a
timestamped
.bashrcbackup before a change.