Skip to content

Security: SSHdotCodes/Cos

Security

SECURITY.md

Security policy

Reporting a vulnerability

Please use GitHub's private vulnerability reporting for SSHDotCodes/Cos when available. If that is not available, contact the repository owner privately through the contact method on the SSHDotCodes GitHub profile. Do not include credentials, private task transcripts, or exploit details in a public issue.

Include the affected Cos version, macOS version, reproduction steps, impact, and any suggested mitigation. You should receive an acknowledgement within seven days.

Supported versions

Security fixes target the latest published release. Older builds should be upgraded before reporting behavior that may already be fixed.

Trust model

Cos executes model-selected tools and can be granted broad filesystem or Accessibility access. Review docs/SECURITY.md before enabling Full Access, installing third-party plugins, or granting Computer Use permissions.

There aren't any published security advisories