Skip to content

Security: OnPoint-Dev-Tools/crewcode

Security

SECURITY.md

Security Policy

CrewCode runs AI coding agents with access to your filesystem, shell, git, and SSH. Security reports are taken seriously.

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues, pull requests, or discussions.

Instead, report privately through GitHub private vulnerability reporting: go to the repository's Security tab and choose "Report a vulnerability". This opens a private advisory that only the maintainer can see.

Please include:

  • a description of the vulnerability and its impact,
  • steps to reproduce (proof-of-concept if possible),
  • affected version or commit, and your environment (OS, local vs. SSH/remote).

What to expect

CrewCode is maintained by a solo developer, so response times are best-effort, but you can expect:

  • an acknowledgement that the report was received,
  • an assessment of validity and severity,
  • a fix or mitigation for confirmed issues, prioritized by severity,
  • credit for the disclosure if you'd like it (let us know your preference).

Please give a reasonable amount of time for a fix before any public disclosure.

Supported versions

As an actively developed solo project, only the latest release receives security fixes. Please make sure you're on the most recent version before reporting.

There aren't any published security advisories