4 Commits
Author SHA1 Message Date
owen 4d021fe2ab Resolve lru advisory for v0.2.5
CI / Test (push) Waiting to run
CI / Build (push) Waiting to run
2026-06-25 05:53:53 -05:00
owen 7c8cc9eac5 Adding a security policy 2026-06-25 05:39:37 -05:00
IrrelevantandGitHub 52c879e7c8 Merge pull request #2 from owenqwenstarsky/add-github-issue-templates
Add GitHub issue templates
2026-06-24 20:58:19 -05:00
owen 60dfdf3806 Add GitHub issue templates 2026-06-24 20:57:00 -05:00
8 changed files with 1177 additions and 107 deletions
+101
View File
@@ -0,0 +1,101 @@
name: Bug report
description: Report a reproducible problem with Cassady / cass
title: "bug: "
labels: [bug]
body:
- type: markdown
attributes:
value: |
Thanks for reporting a bug. Please include enough detail for someone to reproduce it.
- type: textarea
id: summary
attributes:
label: Summary
description: What went wrong?
placeholder: Cassady crashes when...
validations:
required: true
- type: textarea
id: steps
attributes:
label: Steps to reproduce
description: List the exact commands, key presses, or config changes needed to trigger the issue.
placeholder: |
1. Run `cass ...`
2. Press ...
3. See ...
validations:
required: true
- type: textarea
id: expected
attributes:
label: Expected behavior
description: What did you expect to happen?
validations:
required: true
- type: textarea
id: actual
attributes:
label: Actual behavior
description: What happened instead? Paste errors, logs, or terminal output when useful.
render: text
validations:
required: true
- type: input
id: version
attributes:
label: Cassady version
description: Output of `cass --version` or `cassady --version`.
placeholder: cassady 0.2.x
validations:
required: true
- type: dropdown
id: install
attributes:
label: Install method
options:
- Release archive
- cargo install --git
- cargo install --path / local build
- Other
validations:
required: true
- type: dropdown
id: platform
attributes:
label: Platform
options:
- macOS Apple Silicon
- macOS Intel
- Linux x86_64
- Linux ARM64
- Windows x86_64
- Other
validations:
required: true
- type: textarea
id: environment
attributes:
label: Environment details
description: Terminal, shell, provider/model, access mode, and anything notable from `cass check`. Do not include API keys.
placeholder: |
Terminal: ...
Shell: ...
Provider/model: ...
Access mode: ...
`cass check`: ...
- type: textarea
id: config
attributes:
label: Relevant configuration
description: Paste sanitized snippets from `~/.cass/config.json`, `providers.json`, or `models.json` if relevant. Remove API keys and secrets.
render: json
- type: checkboxes
id: checklist
attributes:
label: Checklist
options:
- label: I removed API keys, tokens, and other secrets from this report.
required: true
- label: I searched existing issues for a duplicate.
required: true
+5
View File
@@ -0,0 +1,5 @@
blank_issues_enabled: false
contact_links:
- name: Questions and usage help
url: https://github.com/owenqwenstarsky/cassady/discussions
about: Ask questions, share setup notes, or discuss ideas before filing an issue.
+44
View File
@@ -0,0 +1,44 @@
name: Documentation issue
description: Report missing, confusing, or incorrect documentation
title: "docs: "
labels: [documentation]
body:
- type: textarea
id: location
attributes:
label: Documentation location
description: Link to the page or name the file/section, if known.
placeholder: README.md, docs/providers.md, docs/access-modes.md, ...
validations:
required: true
- type: textarea
id: issue
attributes:
label: What is unclear or incorrect?
description: Describe the gap, mistake, or confusing wording.
validations:
required: true
- type: textarea
id: suggested
attributes:
label: Suggested improvement
description: If you have specific wording or examples in mind, add them here.
- type: dropdown
id: impact
attributes:
label: Impact
options:
- Blocks installation or first use
- Causes incorrect configuration
- Confuses normal usage
- Typo or small polish
- Other
validations:
required: true
- type: checkboxes
id: checklist
attributes:
label: Checklist
options:
- label: I searched existing issues for a duplicate.
required: true
@@ -0,0 +1,59 @@
name: Feature request
description: Suggest an improvement or new capability for Cassady / cass
title: "feat: "
labels: [enhancement]
body:
- type: markdown
attributes:
value: |
Thanks for suggesting an improvement. Please focus on the user problem and desired outcome.
- type: textarea
id: problem
attributes:
label: Problem or use case
description: What are you trying to do, and what makes it hard today?
placeholder: I want to...
validations:
required: true
- type: textarea
id: proposal
attributes:
label: Proposed behavior
description: Describe the change you would like to see.
validations:
required: true
- type: textarea
id: alternatives
attributes:
label: Alternatives considered
description: What workarounds or other designs have you considered?
- type: dropdown
id: area
attributes:
label: Area
options:
- Terminal UI
- Setup and configuration
- Providers and models
- Tools and file editing
- Safety and access modes
- Conversation history and resume
- Documentation
- Packaging and releases
- Other
validations:
required: true
- type: textarea
id: examples
attributes:
label: Examples or mockups
description: Add sample commands, UI text, config snippets, screenshots, or links that clarify the request.
- type: checkboxes
id: checklist
attributes:
label: Checklist
options:
- label: I searched existing issues for related requests.
required: true
- label: This request is in scope for a terminal coding agent, not a general package manager or updater.
required: false
+52
View File
@@ -0,0 +1,52 @@
name: Maintenance task
description: Track internal cleanup, refactoring, testing, CI, or release work
title: "chore: "
labels: [maintenance]
body:
- type: textarea
id: goal
attributes:
label: Goal
description: What should be done, and why?
validations:
required: true
- type: textarea
id: scope
attributes:
label: Scope
description: List concrete files, modules, or workflows that are in scope.
placeholder: |
- src/...
- tests/...
- .github/workflows/...
validations:
required: true
- type: textarea
id: out_of_scope
attributes:
label: Out of scope
description: Note anything this task should intentionally avoid.
- type: textarea
id: acceptance
attributes:
label: Acceptance criteria
description: What must be true before this can be closed?
placeholder: |
- [ ] ...
- [ ] `cargo test --locked --all-targets` passes
validations:
required: true
- type: dropdown
id: area
attributes:
label: Area
options:
- Refactoring
- Tests
- CI
- Release process
- Dependencies
- Documentation maintenance
- Other
validations:
required: true
Generated
+849 -103
View File
File diff suppressed because it is too large Load Diff
+3 -4
View File
@@ -1,6 +1,6 @@
[package]
name = "cassady"
version = "0.2.4"
version = "0.2.5"
edition = "2021"
description = "Cassady/Cass minimal terminal coding agent"
license = "MIT"
@@ -23,13 +23,13 @@ anyhow = "1"
async-trait = "0.1"
chrono = { version = "0.4", features = ["serde"] }
clap = { version = "4", features = ["derive"] }
crossterm = "0.28"
crossterm = "0.29"
dirs = "5"
futures-util = "0.3"
ignore = "0.4"
include_dir = "0.7"
nanoid = "0.4"
ratatui = "0.28"
ratatui = { version = "0.30", default-features = false, features = ["crossterm", "underline-color"] }
regex = "1"
pulldown-cmark = "0.12"
reqwest = { version = "0.12", default-features = false, features = ["json", "rustls-tls", "stream"] }
@@ -37,7 +37,6 @@ serde = { version = "1", features = ["derive"] }
serde_json = "1"
thiserror = "1"
tokio = { version = "1", features = ["macros", "rt-multi-thread", "sync", "time", "process", "io-util"] }
tui-textarea = "0.6"
unicode-width = "0.1"
[dev-dependencies]
+64
View File
@@ -0,0 +1,64 @@
# Security Policy
## Supported Versions
Security updates are provided for the latest released version of Cassady. If you are using an older version, please upgrade to the latest release before reporting an issue, unless the issue also affects the latest release.
| Version | Supported |
| ------- | --------- |
| Latest | ✅ |
| Older releases | ❌ |
## Reporting a Vulnerability
Please do **not** report security vulnerabilities in public GitHub issues, discussions, or pull requests.
To report a vulnerability, use GitHub's private vulnerability reporting for this repository:
1. Open the repository on GitHub.
2. Go to **Security** → **Report a vulnerability**.
3. Include as much detail as you can about the issue, impact, affected versions, and steps to reproduce.
## What to Include
Helpful reports include:
- A description of the vulnerability and likely impact.
- Steps to reproduce or a minimal proof of concept.
- The Cassady version, operating system, shell, and terminal environment.
- Relevant configuration details with secrets removed.
- Any known mitigations or workarounds.
Do not include live API keys, tokens, private prompts, or sensitive project files in a report. Redact secrets before sharing logs or configuration.
## Response Expectations
After a report is received, the maintainer will aim to:
- Acknowledge the report within 7 days.
- Confirm whether the issue is in scope and reproducible.
- Provide status updates when there is meaningful progress.
- Coordinate disclosure timing before publishing details publicly.
Security fixes may be released as patch versions when appropriate. Public disclosure should wait until a fix or mitigation is available, unless otherwise coordinated with the maintainer.
## Scope
Examples of in-scope issues include vulnerabilities in Cassady that could:
- Bypass documented access modes, approval prompts, or workspace boundaries.
- Cause unintended file reads, writes, edits, or shell command execution.
- Leak API keys, provider credentials, chat history, or local configuration.
- Corrupt or expose session data stored under `~/.cass`.
- Introduce unsafe behavior in bundled release artifacts.
Out-of-scope issues generally include:
- Vulnerabilities in third-party model providers or APIs not controlled by this project.
- Prompt-injection behavior that does not bypass Cassady's documented safety controls.
- Issues that require a compromised local machine, shell, dependency cache, or provider account.
- Reports against unsupported older versions that are fixed in the latest release.
## Safe Harbor
Good-faith security research is welcome. Please avoid privacy violations, data destruction, service disruption, and accessing data that does not belong to you. If you follow this policy and make a good-faith effort to avoid harm, the maintainer will not pursue legal action for your research.