Please do not open a public issue for security problems. Report them to security@iugu.com (or through
GitHub's private vulnerability reporting on this
repository). Include the CLI version (iugu --version), your OS, and the steps to reproduce. We acknowledge
reports within two business days and keep you informed until the fix ships.
- Refresh tokens — in the OS keychain (macOS Keychain, Secret Service, Windows Credential Manager) under the
service
iugu-cli, one entry per profile. When no keychain is available the CLI warns once and falls back to~/.config/iugu/credentials.jsonwith mode0600(--credentials-store fileforces it). - Access tokens — in memory only, for the duration of one command.
- Configuration —
~/.config/iugu/config.json(0600): profiles (API host, preferred workspace); never credentials. A project-local store isIUGU_CONFIG_DIR=.iugu(auto-gitignored). - Secrets delivered by change sets — written only where you ask (
--write-env <file>with0600and a.gitignoreentry, or--execin-process substitution); the API delivers each secret once. IUGU_TOKEN(deploy tokens for CI) is read from the environment and never written to disk.- Windows: the same files live under
%USERPROFILE%\.config\iugu. NTFS has no POSIX mode bits, so0600does not apply; the files are protected by the ACLs of your profile directory (private to your account by default).
A secret substituted with --exec is redacted from the command echoed in --json output. The CLI does not send
telemetry.
Every release is built by GitHub Actions from a tag of this repository, signed with
cosign (keyless, GitHub OIDC), and ships an SBOM per archive.
install.sh, the Homebrew cask and the npm shim verify the downloaded archive against the signed
checksums.txt. To verify by hand:
cosign verify-blob \
--certificate checksums.txt.pem --signature checksums.txt.sig \
--certificate-identity-regexp 'github.com/iugu/cli' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
checksums.txt
sha256sum -c checksums.txt --ignore-missingOnly the latest release receives fixes. The --json shapes follow the published API contract
(https://developer.iugu.com/console/api-v1.yaml); breaking changes are announced in the release notes.