Skip to content

Security: TanUIUX/dramaclaw

Security

SECURITY.md

Security Policy

Thanks for helping keep DramaClaw and its users safe.

Supported versions

Branch / release Status
main Actively maintained — fixes land here first
Latest tagged release Patched as needed
Older releases No guaranteed fixes — please upgrade

Reporting a problem

Please do not open a public issue for security reports. Public disclosure before a fix ships puts every self-hosted deployment at risk.

Use either of the following private channels:

When reporting, please include:

  • The version or commit affected
  • A clear description of the issue and the impact you observed
  • Steps to reproduce (proof-of-concept snippets are welcome)
  • Any mitigations you've already found

What happens next

  • We aim to acknowledge new reports within 72 hours.
  • We will agree a disclosure timeline with you — typically 30-90 days between first contact and public advisory, depending on severity.
  • Once a fix ships, we publish a GitHub Security Advisory and credit the reporter unless anonymity is preferred.

Out of scope

The following are unlikely to be treated as security reports:

  • Issues that require physical access to the host
  • Self-inflicted resource exhaustion on a user's own self-hosted deployment
  • Findings in third-party model providers — please report those to the provider directly
  • Content-moderation concerns — please use Discussions instead

Responsible reports make the project stronger. Thank you.

There aren't any published security advisories