| Version | Status |
|---|---|
| 1.x | Supported (GA shipped 2026-05-04 per CHANGELOG.md) |
Please report security issues privately by emailing security@testatlas.dev (placeholder pending org). Do NOT open a public GitHub Issue for security-sensitive reports. We aim to acknowledge within 72 hours and patch high-severity issues within 30 days.
See docs/THREAT_MODEL.md for documented attack surfaces and mitigations, including the curl|sh installer, auto-update propagation, and prompt injection via .claude/commands/.
We follow coordinated disclosure: reporter and maintainers agree on a disclosure date; CVE assigned where appropriate.
Releases ship as signed tarballs with SHA-256 checksums published in GitHub Releases. The install.sh installer pins to a tagged release and verifies checksums.