| Version | Supported |
|---|---|
| 0.8.x | ✅ |
| 0.7.x | ✅ |
| 0.6.x | ✅ |
| 0.5.x | ✅ |
| 0.4.x | ✅ |
| 0.3.x | ✅ |
| 0.2.x | ✅ |
| 0.1.x | ✅ |
GitWhisper enforces defense-in-depth guarantees across local Git interactions, external trackers, and AI providers:
- Credential Host-Binding (Release-Blocking Invariant):
- Developer tokens and credentials for external work-item trackers (e.g. GitHub, Jira) are strictly bound to their canonical hosts.
- Malicious or compromised repository configuration files cannot redirect credential transmission to foreign hosts.
- Redirect & SSRF Protection:
- Outbound HTTP requests strip
Authorizationheaders on cross-origin redirects. - Non-HTTP/HTTPS schemes (
file://,ftp://,gopher://, etc.) are rejected immediately.
- Outbound HTTP requests strip
- Data Isolation & Staged Boundaries:
- Only explicitly staged files (
git diff --cached) are read. - Working tree modifications,
.envfiles, and untracked files are never read, mutated, or sent.
- Only explicitly staged files (
- Secret Scanning & Redaction:
- Multi-layered regex and Shannon entropy scanners identify sensitive tokens prior to AI transmission and replace them with placeholders.
- Commit messages are scanned post-generation to prevent secret regurgitation.
- Prompt Injection & Terminal Sanitization:
- Code diffs and issue payloads are treated strictly as inert data in system prompts.
- Terminal control characters, ANSI escapes, and OSC window title strings are sanitized from all branch names, issues, and commit messages.
If you discover a potential security vulnerability in GitWhisper, please report it responsibly:
- Email: security@ritualdev.com
- Do NOT create a public issue on GitHub for security vulnerabilities.
Please include:
- Description of the issue
- Steps to reproduce
- Potential impact
We will review reports promptly and publish patches in accordance with responsible disclosure practices.