Skip to content

Security: Portfoligno/kavelune

Security

SECURITY.md

Security policy

Kavelune does not yet have a verified private vulnerability intake. Do not open a public issue for a suspected vulnerability. Preserve a local report and use the private Kavelune route only after it is published in the support contract.

This policy covers this fork's source and its CI-built Linux and macOS release archives, bundled helpers, signatures, provenance, and release evidence. It does not cover OpenAI services or upstream OpenAI Codex. If a finding also affects the upstream project, report it separately through OpenAI's vulnerability disclosure program.

The fork is independently maintained. Do not send fork-only security reports to OpenAI, and do not infer authority from the configured Git remote.

See docs/security.md for the application's sandbox, approval, and network-control boundaries.

There aren't any published security advisories