| Version | Supported |
|---|---|
| Latest release | Yes |
If you discover a security vulnerability in cmux-resurrect, please report it responsibly:
- Email: forge@drolosoft.com
- Subject:
[SECURITY] cmux-resurrect — <brief description>
Please include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
We will acknowledge receipt within 48 hours and provide a timeline for a fix.
Do not open a public GitHub issue for security vulnerabilities.
- Local by default: crex operates on the local filesystem. Network access is limited to
crex update, which queries the GitHub API and downloads releases (honoringGITHUB_TOKENif set); every other command is local-only. - No credentials stored: Layout files contain workspace names, directory paths, split configurations, pane commands, and AI-session resume IDs. No passwords, API keys, or tokens.
- File permissions: Saved layouts are written with mode
0600under~/.config/crex/.