mirror of
https://github.com/hansjone/oclaw.git
synced 2026-10-09 04:40:45 +08:00
Include SECURITY.md for private vulnerability reporting; fix CONTRIBUTING upstream URL. Co-authored-by: Cursor <cursoragent@cursor.com>
21 lines
699 B
Markdown
21 lines
699 B
Markdown
# Security policy
|
|
|
|
## Supported versions
|
|
|
|
Security fixes are applied on the default branch (`main`) when practical. Use the latest commit for deployments.
|
|
|
|
## Reporting a vulnerability
|
|
|
|
Please **do not** open a public GitHub issue for undisclosed security problems.
|
|
|
|
Use **GitHub private vulnerability reporting** for this repository:
|
|
|
|
[Submit a private security advisory](https://github.com/hansjone/oclaw/security/advisories/new)
|
|
|
|
Include:
|
|
|
|
- A short description of the impact
|
|
- Steps to reproduce (or proof-of-concept) if you can share them safely
|
|
- Affected component or path (if known)
|
|
|
|
We will treat reports as confidential and coordinate a fix and disclosure timeline with you when possible.
|