Report security issues privately via a GitHub security advisory. Please do not open a public issue for a suspected vulnerability.
We aim to acknowledge reports within 5 business days. Please include the affected version (see RELEASE-INFO.txt), reproduction steps, and impact.
This server holds a bearer token (SYSMLV2_TOKEN) in its environment and
enforces an HTTPS-or-loopback rule on the API endpoint. Reports about token
handling, SSRF, or the staged-commit confirmation flow are especially
welcome.
Non-security questions: open an issue, or contact support@jgsystemsconsulting.com.