EN
Security

How GenPM protects your project

Secure by design, verifiable by anyone. We never promise 100 %: we promise invariants with tests that block every release.

Invariants

  1. INV-1 Integrity: the installed bytes are exactly the commit’s tree.
  2. INV-2 Zero execution: GenPM never runs package code or hooks.
  3. INV-3 Confinement: writes stay inside your project, in planned paths.
  4. INV-4 No executables: injected files never keep execute permissions.
  5. INV-5 Consent: no MCP config, npm installs or overwrites without your yes.
  6. INV-6 Secrets: GenPM never reads .env values.
  7. INV-7 Registry authority: publishing reads GitHub, never the client.
  8. INV-8 Signed manifests: the CLI only installs registry-signed manifests.
  9. INV-9 Immutability: a published version never changes.
  10. INV-10 Tenant isolation: no query crosses registries.

Report a vulnerability

Email hello@genpm.net (subject [SECURITY]) or use GitHub Private Vulnerability Reporting. First response within 48 hours. Safe harbor for good-faith research.