Security fixes are applied to the latest release on the main branch (PyPI
package agent-tokenops). Older 0.x releases are not patched separately while the
project is in alpha.
Please do not open a public GitHub issue for security reports.
Use GitHub Security Advisories to send a private report. Include:
- A clear description of the issue and impact
- Steps to reproduce (or a proof of concept if safe to share privately)
- Affected versions / commit SHA if known
We will acknowledge receipt as soon as we can, assess severity, and coordinate a fix and disclosure timeline with you. Please give us reasonable time to ship a fix before any public discussion.