This tool deletes files — that is the feature, so a bug in it can be data loss. The safety model (age gates, process liveness, lock interlocks, rename-first removal, fail-closed probes) is documented in the README; if you find a way it can remove something it shouldn't, that report is especially welcome.
- Preferred: GitHub private vulnerability reporting
- Otherwise: mail
danil@nddev.it.comwith[rldyour-cleaner]in the subject.
Please include the platform, the policy in effect (rldyour-cleaner config),
what was deleted (or would be, via run --dry-run), and why that was wrong.
- "It deleted a directory" is only a bug if a guard should have stopped it —
stale
target/dirs are exactly what it removes. - The install scripts verify release assets by SHA-256; a compromised download is rejected, not installed.
- The tool never touches credentials,
.gitcontents, or paths matchingprotect; it cannot escalate privileges (the only privileged step is an optional, user-invokedsudo installof a tmpfiles drop-in on Linux).
Only the latest release receives fixes.