Currently supported versions with security updates:
| Version | Supported |
|---|---|
| 0.2.x | ✅ |
| < 0.2 | ❌ |
We take security seriously. If you discover a security vulnerability, please follow these steps:
- Open a public GitHub issue
- Disclose the vulnerability publicly before it's been addressed
-
Email us directly at myprojectjisan@gmail.com with:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
-
Wait for acknowledgment - We'll respond within 48 hours
-
Coordinate disclosure - We'll work with you on timing
- Never commit API keys to the repository
- Use environment variables or config files (excluded from git)
- Rotate keys if accidentally exposed
- jevXagent runs on localhost by default (127.0.0.1)
- Do not expose the proxy to public networks without proper security
- Use HTTPS for production deployments
- jevXagent logs metrics but not request content
- API keys are never logged
- Review logs before sharing for debugging
When using jevXagent:
- Keep dependencies updated - Run
pip install --upgrade - Review configuration - Check
~/.jevxagent/config.jsonpermissions - Monitor logs - Watch for suspicious activity
- Use latest version - Update to get security patches
- Limit network exposure - Keep proxy localhost-only
We appreciate responsible disclosure and will acknowledge security researchers who help improve jevXagent's security (with permission).