Skip to content

Security: pikachuprogrammer01/cbm-projects

Security

SECURITY.md

Security policy

Supported versions

Security fixes are provided for the latest released version.

Reporting

Please report vulnerabilities privately through GitHub Security Advisories for this repository. Do not include private source code, credentials, or local index databases in a public issue.

Trust boundaries

  • MCP installation is opt-in and delegated to the public DeusData/codebase-memory-mcp installer.
  • Remote plugin installation requires an explicit SHA-256 checksum.
  • Release installers verify cbm-projects archives against the release checksums.txt file.
  • Process plugins run with the current user's operating-system permissions. Manifest permissions are disclosures, not a sandbox.
  • Project paths and graph indexes remain local unless another explicitly installed plugin sends them elsewhere.

There aren't any published security advisories