Please do not open public issues for security vulnerabilities.
To report a vulnerability, use GitHub Security Advisories. This ensures that the report remains private until a fix is available.
- A description of the vulnerability
- Steps to reproduce or a proof of concept
- The potential impact
- Any suggested fix (optional)
We will respond on a best-effort basis.
- Vulnerabilities in third-party dependencies (please report these upstream)
- Vulnerabilities in Claude Code CLI itself (please report to Anthropic)
- Issues that require physical access to the machine running sabori-flow
We follow coordinated disclosure practices:
- Vulnerability details will not be published until a fix is available
- Credit will be given to reporters in the release notes (unless they prefer to remain anonymous)
- We aim to coordinate disclosure timelines with the reporter