Skip to content

Security: WorldBrain/handoffs

SECURITY.md

Security policy

Handoffs crosses a sensitive boundary between remote services and a user's local development environment. Please do not report suspected vulnerabilities in a public issue.

Use GitHub's private vulnerability reporting for this repository: open the Security tab, choose Advisories, then Report a vulnerability. Include:

  • the affected version or commit;
  • the operating system and installation method;
  • reproduction steps and observed impact;
  • any suggested mitigation; and
  • whether you intend to disclose the issue publicly.

Do not include live provider grants, Codex credentials, private repository contents, or other users' data. We will acknowledge a complete report within five working days and coordinate disclosure after a fix is available.

Until the first signed release is published, treat all repository artifacts as experimental and unsuitable for protecting production credentials.

There aren't any published security advisories