Security fixes are considered for the current main branch. Tagged release
support will be documented here when this project starts publishing versioned
binary or package releases.
Use GitHub Security Advisories for private reports when available. If that is
not available, email support@51code.tw with a subject that starts with
Security: simulator-broker. Do not open a public GitHub issue for
vulnerability reports.
Do not include live credentials, private machine paths, private task links, or third-party customer data in public issues, pull requests, logs, or examples.
Useful private report details include:
- affected command, script, or app surface
- exact version or commit
- reproduction steps using synthetic data
- observed impact
- any safe, redacted logs