oclaw/SECURITY.md
oliver 19e51e2c12 docs: add MIT license, security policy, and README legal section
Include SECURITY.md for private vulnerability reporting; fix CONTRIBUTING upstream URL.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-04 12:53:56 +08:00

699 B

Security policy

Supported versions

Security fixes are applied on the default branch (main) when practical. Use the latest commit for deployments.

Reporting a vulnerability

Please do not open a public GitHub issue for undisclosed security problems.

Use GitHub private vulnerability reporting for this repository:

Submit a private security advisory

Include:

  • A short description of the impact
  • Steps to reproduce (or proof-of-concept) if you can share them safely
  • Affected component or path (if known)

We will treat reports as confidential and coordinate a fix and disclosure timeline with you when possible.