Skip to content

Security: PhamBit/goldberry

Security

SECURITY.md

Security Policy

Scope

GoldBerry is primarily a framework/documentation repository with a small Python tooling layer.

Security-relevant issues may include:

  • malicious or unsafe code in the Python package
  • prompt-packaging behavior that leaks local data unexpectedly
  • unsafe handling of local files in the CLI
  • supply-chain issues in packaging or dependencies
  • site content that introduces security risk

Reporting

Please report suspected security issues privately to the maintainers before opening a public issue.

When reporting, include:

  • affected file(s)
  • reproduction steps
  • impact assessment
  • any suggested mitigation

What to expect

Maintainers will aim to:

  • acknowledge the report
  • assess severity
  • fix or mitigate where appropriate
  • publish a public note once disclosure is safe

Non-security issues

General bugs, documentation problems, and methodology critiques should go through the normal issue tracker.

There aren’t any published security advisories