Skip to content

Security: eyeinthesky6/codex-coordinator

SECURITY.md

Security Policy

Supported versions

While the project remains on the 0.x line, only the latest published release and the default branch receive security fixes. Older releases should be upgraded rather than patched in place.

Reporting a vulnerability

Do not open a public issue or include exploit details in a normal support request.

Once this repository is hosted on GitHub, use Security → Report a vulnerability to submit a private vulnerability report. Include:

  • affected version or commit;
  • impact and realistic attack conditions;
  • minimal reproduction steps;
  • any suggested mitigation.

If private vulnerability reporting is unavailable, contact a maintainer through their GitHub profile and ask for a private reporting channel before sharing details.

Relevant reports include command execution, path traversal, message or ownership spoofing, unsafe bootstrap behavior, and accidental exposure of project coordination data.

There aren't any published security advisories