SandBase CLI configures MCP clients and stores local credentials, so security and configuration ownership are treated as product requirements.
Security fixes are provided in the latest verified GitHub release. The npm latest tag may temporarily lag while trusted publishing is being enabled.
| Version | Supported |
|---|---|
| v0.1.17 | Yes |
| Earlier versions | No |
Install or diagnose the supported release from its immutable artifact:
npx -y https://github.com/sandbaseai/cli/releases/download/v0.1.17/sandbaseai-cli-0.1.17.tgz doctorUse GitHub private vulnerability reporting. Include the affected command and version, impact, reproduction steps, and sanitized diagnostic output.
Do not open a public Issue for vulnerabilities. Never include API keys, access tokens, credentials, private configuration, working exploit details, or user data in public discussions.
For ordinary bugs that do not expose credentials or cross a security boundary, use the bug report form.
Maintainers will acknowledge actionable reports, assess affected versions, and coordinate a fix and disclosure through the private advisory. Please allow reasonable time to investigate before publishing exploit details.
Do not test against accounts, systems, or data you do not own or have explicit permission to use.