Skip to content

Security: op-q/blob

Security

.github/SECURITY.md

Security Policy

Supported Versions

Security fixes are applied to the latest release and the current dev branch. Older snapshots may not receive patches.

Reporting a Vulnerability

Do not open a public issue for a suspected vulnerability.

Email hello@lifbom.com with the subject SECURITY: <short summary>. Include the affected surface, impact, reproduction steps or proof of concept, and the commit or version when known.

You should receive an acknowledgement within five business days. Please allow a reasonable investigation and remediation window before disclosure.

Scope

  • This repository and its release artifacts.
  • The hosted API at api.blob.lifbom.com.
  • The account website at blob.lifbom.com.

Especially useful reports include authentication or authorization bypasses, cross-user data access, RLS failures, credential exposure, connector approval-gate bypasses, SSRF, unsafe tool execution, and actions occurring without the required user approval.

Rules of Engagement

  • Do not access, change, or destroy another user's data.
  • Do not perform denial-of-service, spam, social engineering, or physical attacks.
  • Do not run automated scans against hosted services without written permission.
  • Use test accounts and the smallest proof necessary.
  • If you encounter a credential, report it without using it.

Good-faith research following these rules will not be pursued by the project maintainers.

There aren't any published security advisories