Skip to content

Security: mstallone/runway

SECURITY.md

Security Policy

Reporting a vulnerability

Do not open a public issue. Open a private vulnerability report on GitHub instead. The report stays private until a fix is released.

Include:

  • A description of the vulnerability
  • Steps to reproduce
  • Affected versions
  • Impact (what can an attacker do?)

Response timeline

  • Acknowledgment within 48 hours
  • Assessment and plan within 7 days
  • Fix released as soon as practical, depending on severity

Scope

In scope:

  • The Runway desktop application
  • The built-in providers (credential handling, API calls)
  • The local HTTP API
  • Build and release infrastructure

Out of scope:

  • Third-party provider APIs (report to the provider)
  • Social engineering
  • Denial of service

Supported versions

Only the latest release receives security updates.

There aren't any published security advisories