Skip to content

Security: arasovic/pi-worker

SECURITY.md

Security

The supported release line is v0.1.x.

Workers execute bash with the current user's permissions in the current writable workspace. Pi Worker is not a sandbox.

Do not post credentials, Pi profiles, provider configuration, prompts, workspace contents, or sensitive logs in public issues. Do not disclose a vulnerability publicly.

Use GitHub private vulnerability reporting. If that channel is unavailable, do not disclose publicly or send secrets elsewhere. Publication requires the private reporting channel to be enabled first.

There aren't any published security advisories