Skip to content

Security: max-now/MaxOS-Spec

SECURITY.md

Security Policy

Supported Versions

MaxOS is an engineering preview. Security fixes are made on the latest main revision only. Historical drafts and downstream forks are not maintained by this project.

Reporting a Vulnerability

Do not report suspected vulnerabilities in a public issue, discussion, or pull request.

Use GitHub private vulnerability reporting from the repository's Security tab. If Report a vulnerability is not available, contact a repository maintainer through their GitHub profile without including sensitive details and ask for a private reporting channel.

Include:

  • the affected revision and component;
  • prerequisites and a minimal reproduction;
  • the expected and observed security boundary;
  • potential impact;
  • any known mitigations; and
  • whether the report contains secrets, personal data, or third-party data.

Maintainers aim to acknowledge a complete report within five business days. Timelines for validation, remediation, and disclosure depend on severity and scope. Please allow maintainers a reasonable opportunity to investigate before public disclosure.

This project does not operate a bug-bounty program and cannot promise payment.

Scope

Reports are especially useful when they concern:

  • identity, Human Owner, or employee-scope confusion;
  • credential disclosure or mediation bypass;
  • unauthorized Tool execution or external-system access;
  • cross-Company or cross-employee memory access;
  • approval, Run, audit, or workflow-integrity failures;
  • sandbox or local-worker boundary escapes; or
  • secrets committed to this repository.

Model quality, prompt preferences, and behavior already identified as an explicit reference limitation are not security vulnerabilities unless they cross a declared trust or authorization boundary.

There aren't any published security advisories