Skip to content

Security: stef-k/agent-code-guard

SECURITY.md

Security Policy

Reporting a vulnerability

Do not report suspected security vulnerabilities through public GitHub issues. Use GitHub's private vulnerability reporting instead, and do not post exploit details, credentials, private repository content, access tokens, or other sensitive information publicly.

Use the private route for vulnerabilities that could compromise users, repositories, execution environments, package or release integrity, or other security-sensitive behavior. This policy concerns vulnerabilities in Agent Code Guard or its distribution and workflows; it does not mean Agent Code Guard is a security-analysis product.

Reports will be reviewed as maintainer availability permits.

Support posture

Until 1.0, security maintenance is best-effort for the current development line and latest available release. Older versions may not receive backports.

There aren't any published security advisories