Security fixes are applied to the latest released version of Echo. Development snapshots may change without notice.
Do not open a public issue for a suspected vulnerability. Use the repository hosting platform's private vulnerability-reporting feature (the Security tab) and include affected version, reproduction steps, impact, and a safe proof of concept. Do not include credentials, access tokens, or private source code.
Maintainers aim to acknowledge reports within 7 days and provide a status update within 30 days. Public disclosure is coordinated after a fix or an agreed mitigation is available.
Relevant reports include workspace escape, unintended file disclosure, token exposure, unsafe remote transport behavior, and package supply-chain issues. Codex, Pi, and user-operated app-server deployments are separate products; please report their vulnerabilities to their respective maintainers as well.