Security fixes are applied to the latest release and the current main branch. Older source snapshots are not supported unless a release note says otherwise.
Please use the repository's Security → Report a vulnerability flow to submit a private GitHub security advisory. If that flow is unavailable, contact the maintainers through a private contact method listed on the alcheme-labs organization profile. Do not open a public issue for an unpatched vulnerability and do not include credentials, API keys, private prompts, or user workspace data in a report.
Include the affected version or commit, impact, reproduction steps, and any suggested mitigation. Maintainers will acknowledge the report as soon as practical, validate the issue, and coordinate disclosure after a fix is available.
Relevant security boundaries include:
- workspace path isolation and file access;
- shell, Git, network, and secret approval policies;
- API Key storage and redaction;
- local HTTP/WebSocket control-token enforcement;
- model-provider endpoint validation;
- dependency or desktop packaging vulnerabilities.
Only test systems and data you are authorized to access.