Do not open public issues for security bugs.
Use GitHub's Private vulnerability reporting on this repository.
If unavailable, email security@pleme.io with a description, affected versions, and reproduction steps.
| Step | Target |
|---|---|
| Acknowledgement | 5 business days |
| Triage + severity | 10 business days |
| Coordinated disclosure | 90 days from acknowledgement |
In scope:
- The Rust crate at
src/— generator correctness, output safety - Generated Python module shape (escape correctness, no command injection, etc.)
- The
module_utils/akeyless_client.pyhelper bundled insrc/client_helper.rs
Out of scope (report upstream):
- The
iac-forgeIR or resolver →pleme-io/iac-forge - The Akeyless API itself → Akeyless support
- The published Ansible collection →
pleme-io/ansible-akeyless-gen
| Version | Status |
|---|---|
0.2.x |
Active |
< 0.2 |
Unsupported |