Skip to content

Security: davebream/tila

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.2.x Yes
0.1.x No

Reporting a Vulnerability

Do not open a public issue for security vulnerabilities.

Please report security vulnerabilities through GitHub's private vulnerability reporting:

  1. Go to the Security Advisories page
  2. Click "Report a vulnerability"
  3. Fill in the details of the vulnerability

You will receive an acknowledgment within 48 hours. We will work with you to understand the scope and develop a fix before any public disclosure.

Scope

This policy applies to:

  • The tila Worker and Durable Object backend
  • The tila CLI
  • The tila SDK and MCP server
  • Authentication and token handling

Preferred Languages

We accept vulnerability reports in English.

There aren't any published security advisories