Skip to content

Security: Stunspot/CanopyOps

SECURITY.md

Security Policy

Supported release

Security fixes are considered for the current v0.1.5 release line. Earlier public releases remain available as historical artifacts but are superseded; private prototype snapshots are retained only as development evidence.

What counts as a security concern

Relevant reports include:

  • path traversal or unintended file access;
  • unsafe archive creation or extraction;
  • execution of untrusted files or discovered project code;
  • command injection or unsafe script arguments;
  • exposure of secrets or sensitive cultivation records;
  • misleading permission, telemetry, connector, or network behavior;
  • a prompt or workflow path that encourages unauthorized external action;
  • packaging that silently crosses the documented trust boundary.

CanopyOps v0.1.5 contains no hosted service, account, telemetry, connector, MCP server, hook, or automatic network request.

Report privately

Use CanopyOps private vulnerability reporting. If that route is unavailable, contact Collaborative Dynamics through https://collaborative-dynamics.com and request a private reporting route before sending technical details.

Do not open a public issue containing exploit instructions, credentials, facility security information, personal data, proprietary cultivation records, or other sensitive material.

What to include

  • affected version and file;
  • host and operating system;
  • minimal reproduction using synthetic data;
  • impact and required preconditions;
  • whether the issue has been disclosed elsewhere;
  • any safe mitigation already identified.

Coordinated handling

Collaborative Dynamics may confirm receipt, request a safer reproduction, assess scope, prepare a fix, and coordinate disclosure. No bounty, response deadline, or disclosure embargo is promised unless agreed separately in writing.

There aren't any published security advisories