Trust and Security

Verified statements about FlagLint's identity, data handling, and release posture. Every claim is grounded in source code, repository configuration, or published package metadata.

What FlagLint is

Data handling

Verification

The read-only and source-editing behavior above is grounded in the current command implementations and tests. Source: github.com/flaglint/flaglint

Release and CI

The release workflow publishes to npm through GitHub Actions using npm Trusted Publishing/OIDC. Every release runs the full test suite on Node.js 20 and Node.js 22 before publication. CI also runs CodeQL static analysis and Dependabot dependency updates. Runtime support: Node.js 20 or newer.

Security reporting

Report suspected vulnerabilities privately through GitHub Security Advisories. For false positives or unsupported patterns, use the unsupported-pattern issue template. See SECURITY.md for the full security policy.

Project links