Security
How GenPM protects your project
Secure by design, verifiable by anyone. We never promise 100 %: we promise invariants with tests that block every release.
Invariants
INV-1Integrity: the installed bytes are exactly the commit’s tree.INV-2Zero execution: GenPM never runs package code or hooks.INV-3Confinement: writes stay inside your project, in planned paths.INV-4No executables: injected files never keep execute permissions.INV-5Consent: no MCP config, npm installs or overwrites without your yes.INV-6Secrets: GenPM never reads .env values.INV-7Registry authority: publishing reads GitHub, never the client.INV-8Signed manifests: the CLI only installs registry-signed manifests.INV-9Immutability: a published version never changes.INV-10Tenant isolation: no query crosses registries.
Report a vulnerability
Email hello@genpm.net (subject [SECURITY]) or use GitHub Private Vulnerability Reporting. First response within 48 hours. Safe harbor for good-faith research.