Please report security issues privately — do not open a public issue.
Email support@xns.tech with SECURITY in the subject line. Include:
- what you found and where (file, command, or credential path),
- the steps to reproduce it,
- what an unauthorized party could do with it,
- the
xns versionoutput you tested.
You will get an acknowledgement within five business days. Please give us a reasonable window to ship a fix before disclosing publicly.
XNS-specific code (command/xns_*.go, the credential store, and the MCP
integration) is in scope for this address. Issues in the upstream
s5cmd code this project is built on should
also be reported here — we will coordinate upstream where appropriate.
xns is pre-release. Fixes land on the latest beta tag; there is no
long-term-support branch yet.