Skip to content

Security: sunpe/echo

Security

SECURITY.md

Security Policy

Supported versions

Security fixes are applied to the latest released version of Echo. Development snapshots may change without notice.

Reporting a vulnerability

Do not open a public issue for a suspected vulnerability. Use the repository hosting platform's private vulnerability-reporting feature (the Security tab) and include affected version, reproduction steps, impact, and a safe proof of concept. Do not include credentials, access tokens, or private source code.

Maintainers aim to acknowledge reports within 7 days and provide a status update within 30 days. Public disclosure is coordinated after a fix or an agreed mitigation is available.

Scope

Relevant reports include workspace escape, unintended file disclosure, token exposure, unsafe remote transport behavior, and package supply-chain issues. Codex, Pi, and user-operated app-server deployments are separate products; please report their vulnerabilities to their respective maintainers as well.

There aren't any published security advisories