Files
skills-vault/SECURITY.md
T
2026-03-27 10:51:14 +08:00

1.9 KiB

Security Policy

Supported Versions

Security fixes are handled on a best-effort basis for:

  • the latest published npm release of skvlt
  • the current main branch in this repository

Older versions may receive guidance, but they should not be assumed to receive patches.

Reporting a Vulnerability

Please do not open public GitHub issues or pull requests for suspected vulnerabilities.

Preferred reporting path:

  1. Use GitHub Private Vulnerability Reporting for this repository if it is available.
  2. If private vulnerability reporting is not available, use the private maintainer contact methods listed at xi-xu.me/contact and clearly label the message as a security report for skills-vault.

Please include:

  • a description of the issue and impact
  • affected versions or commit range, if known
  • reproduction steps or a proof of concept
  • any suggested remediation, if you already have one

Response Expectations

This project is maintained on a best-effort basis, but the goal is to:

  • acknowledge new reports within 5 business days
  • keep the reporter updated on triage status when material progress is made
  • coordinate public disclosure after a fix or mitigation is available

Scope

This policy covers vulnerabilities in this repository, including:

  • CLI command behavior
  • manifest parsing and install planning
  • release and packaging configuration in this repository

If a report only affects an upstream dependency or the external Skills CLI itself, it may need to be reported upstream as well.

Security Practices in This Repo

This repository already uses several baseline security controls, including dependency review automation and locked Bun installs in CI. Additional repository settings such as branch protection, MFA for privileged contributors, and GitHub private vulnerability reporting should stay enabled wherever available.