Files
skills-vault/SECURITY.md
T

1.3 KiB

Security Policy

Supported Versions

Security fixes are applied on a best-effort basis to the latest development state on main and the latest published package version.

Older releases may not receive fixes.

Reporting a Vulnerability

Please do not report security vulnerabilities in public GitHub issues or pull requests.

Instead, report them privately to [email protected]. If GitHub private vulnerability reporting is enabled for this repository, you may use the repository's "Report a vulnerability" flow instead.

Please include:

  • A clear description of the issue
  • Affected version or commit, if known
  • Reproduction steps or a proof of concept
  • Impact assessment, if you have one
  • Suggested remediation, if available

What to Expect

  • We will review reports as quickly as possible.
  • We may ask follow-up questions to confirm impact and scope.
  • We will aim for coordinated disclosure and a fix before public discussion.
  • When appropriate, we will document the fix in a release note or security advisory.

Out of Scope

The following are usually not treated as security vulnerabilities by themselves:

  • Requests for help with local environment setup
  • Reports that only affect unsupported or heavily modified environments
  • General dependency hygiene suggestions without a demonstrated impact on this project