Skip to content

Security: mgoelz/decision-layer

Security

SECURITY.md

Security Policy

Reporting a vulnerability

If you believe you have found a security issue in DecisionLayer, please do not open a public issue with exploit details.

Instead:

  1. report it privately to the maintainers once a security contact is established
  2. include clear reproduction steps
  3. include impact, affected files or packages, and suggested mitigations if known

Until a dedicated security contact exists, maintainers should set one up before the first public release.

Scope

Security reports are especially relevant for:

  • local file parsing and bundle discovery
  • CLI execution paths
  • future IDE integrations
  • future agent or hook integrations
  • any code that reads untrusted repository content

Supported versions

Pre-1.0.0: best effort.

There aren't any published security advisories