-
Notifications
You must be signed in to change notification settings - Fork 0
SECURITY_RESPONSE
github-actions[bot] edited this page Jul 19, 2026
·
2 revisions
- Contain without reproducing sensitive content in logs, issues, or chat.
- Classify affected data, provider, version, exploitability, and severity.
- Revoke credentials and consent grants; preserve sanitized evidence.
- Fix on a private branch and add a fictional-data regression test.
- Run tests, Ruff, mypy, Semgrep, dependency audit, secret scan, and SBOM diff.
- Coordinate history rewriting and user notification if private data escaped.
- Publish a concise advisory, upgrade guidance, and control-matrix update.
Critical and High issues remain release blockers until disposition is documented.
- Home
- CLI reference
- Interactive console guide
- Architecture ownership and dependency contracts
- Bounded file ingress
- Versioning and compatibility
- Continuous integration
- Release runbook
- Encrypted backup and recovery
- First-run storage diagnostics
- GEDCOM compatibility and release checks
- Built-in module authoring
- Privacy and consent
- Provider guide
- Local LLM benchmarks
- Local-first retrieval evaluation
- Wiki synchronization
- Wiki operations and recovery
- Security response checklist
- Electron and FastAPI desktop ADR
- Data-flow threat model and control matrix