code-review-loop is pre-1.0 software. Security fixes are provided for the
current main branch and the most recent tagged release once public releases
begin.
Use GitHub Private Vulnerability Reporting as the primary channel:
https://github.com/GitCmurf/revrem/security/advisories/new
If that channel is unavailable, email colinfarmer.gg1@gmail.com with a short
summary and reproduction details.
Do not paste credentials, private logs, local Codex transcripts, or other secrets into public issues, discussions, or pull requests.
- affected version or commit;
- operating system and Python version;
- minimal reproduction steps;
- expected and actual behavior;
- whether secrets, local artifacts, or generated remediation output are involved.
The maintainer will acknowledge confirmed reports as soon as practical, triage impact, and coordinate a fix or disclosure path through the private advisory thread.