Skip to content

Security: ashlrai/ashlr-stack

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
v0.1.x Security patches only

Reporting a Vulnerability

Do not file a public GitHub issue for security vulnerabilities.

Report via GitHub Security Advisories: https://github.com/ashlrai/ashlr-stack/security/advisories/new

We will acknowledge within 3 business days, triage within 7, and coordinate disclosure timing with you before any public release.

Scope

In scope: @ashlr/stack CLI, ashlr-stack-mcp MCP server, @ashlr/stack-core package, and any published npm packages in this repo.

Out of scope: Third-party provider APIs (Supabase, Vercel, etc.) and Phantom Secrets itself — report Phantom issues via Phantom's own disclosure channel.

Credits

We're glad to credit reporters in release notes. If you prefer anonymity, just say so in your report.

There aren’t any published security advisories