Skip to content

Security: MPIsaac-Per/claude-code-ops-audit

SECURITY.md

Security policy

Supported versions

Security fixes are applied to the latest commit on main. This project has not published a stable release series yet.

Reporting a vulnerability

Use GitHub private vulnerability reporting. Do not open a public issue or attach raw logs, prompts, paths, credentials, account identifiers, or customer data.

Include a synthetic reproduction, affected files, impact, and proposed mitigation. You can expect an acknowledgement within five business days. Disclosure timing will be coordinated after validation and remediation.

Data handling

Claude Code JSONL logs can contain source code, credentials, file paths, prompts, command output, and personal data. Run the pipeline on storage you control, restrict database access, and review every export before sharing it. This repository does not need or accept private corpora.

There aren't any published security advisories