Skip to content

Security: FasterApiWeb/skill-orchestrator

Security

SECURITY.md

Security Policy

Supported versions

We publish security fixes for the latest minor release on main. Older tags may not receive backports.

Reporting a vulnerability

Please do not open public GitHub issues for undisclosed security bugs.

Instead, email security@example.com with:

  • A description of the issue and its impact
  • Steps to reproduce (proof-of-concept if possible)
  • Affected versions or commit SHAs

We aim to acknowledge reports within three business days.

Supply chain

  • Run npm audit locally before publishing.
  • CI enforces high/critical audit gates and uploads coverage to Codecov.
  • Skill packages should be validated (checksum, manifest review) before installation in sensitive environments.

There aren’t any published security advisories