If you discover a security vulnerability in rmb, please do not open a public issue.
Instead, report it privately by emailing security@kerryhatcher.com.
We will respond within 48 hours to acknowledge your report and begin investigating. We will work with you on a fix and coordinate a disclosure timeline.
| Version | Supported |
|---|---|
| 0.1.x (main) | ✅ Active development |
| Future 1.x | ✅ Will be supported |
As rmb is pre-1.0, only the latest commit on main is actively supported.
To help us triage quickly, please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce the issue
- The version/commit of
rmbyou're using - Any relevant logs or error output
- Reporter submits vulnerability privately
- Maintainers acknowledge within 48 hours
- Maintainers investigate and develop a fix
- A security advisory is published on GitHub with the fix
- Credit is given to the reporter (unless they prefer to remain anonymous)
- Always use the latest release of
rmb - Be cautious when installing plugins from untrusted sources —
rmb installclones and executes code from git repositories - Review plugin source code before installing, especially for plugins that modify your Pi or Claude Code configuration