Do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting feature on this repository. Include affected versions, reproduction steps, impact, and any suggested mitigation. Avoid including live credentials or private source code.
There is not yet a guaranteed response SLA for this early-stage project.
Until the first stable release, only the latest commit on the default branch is supported with security fixes.
BYOA Runtime executes coding agents with the privileges of the daemon's local OS
account. It supplies authentication, admission policy, durable orchestration, and
protocol isolation; it does not provide an OS sandbox. See docs/security.md for
the complete trust model.