Skip to main content

Vulnerability Reporting

How to Report

Preferred: GitHub Security Advisories

  1. Navigate to the Security tab on our GitHub repository
  2. Click "Report a vulnerability"
  3. Fill in the details (type, affected component, reproduction steps, impact)

Disclosure Process

  1. Reporter submits vulnerability
  2. We acknowledge within 48 hours
  3. We assess severity within 7 days
  4. We develop and test a fix
  5. We release the fix
  6. We publicly disclose (with reporter credit, if desired)

Recognition

With your permission, we will:

  • Credit you in the security advisory
  • Add you to our security acknowledgments
  • Provide a letter of appreciation (upon request)

Security Updates

  • Security updates are released as patch versions
  • Agents support self-updating for rapid deployment
  • Watch this repository for releases
  • Subscribe to GitHub security advisories