Skip to content

Security: nonz250/sabori-flow

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Please do not open public issues for security vulnerabilities.

To report a vulnerability, use GitHub Security Advisories. This ensures that the report remains private until a fix is available.

What to Include

  • A description of the vulnerability
  • Steps to reproduce or a proof of concept
  • The potential impact
  • Any suggested fix (optional)

We will respond on a best-effort basis.

Out of Scope

  • Vulnerabilities in third-party dependencies (please report these upstream)
  • Vulnerabilities in Claude Code CLI itself (please report to Anthropic)
  • Issues that require physical access to the machine running sabori-flow

Disclosure Policy

We follow coordinated disclosure practices:

  • Vulnerability details will not be published until a fix is available
  • Credit will be given to reporters in the release notes (unless they prefer to remain anonymous)
  • We aim to coordinate disclosure timelines with the reporter

There aren't any published security advisories