Skip to content

Security: DevFoundry-labs/configledger

SECURITY.md

Security Policy

Supported versions

Security fixes are provided for the latest released minor version.

Reporting a vulnerability

Use GitHub private vulnerability reporting for DevFoundry-labs/configledger. If that feature is unavailable, contact the repository owner through the private contact method on the GitHub profile. Do not open a public issue containing exploit details or secrets.

Include the affected version, operating system, reproduction steps using synthetic data, impact, and suggested mitigation if known. You can expect acknowledgement within seven days and status updates at least every fourteen days while the report is active.

Scope priorities

  • Reading outside the selected root.
  • Execution of repository-controlled content.
  • Exposure of raw configuration values in output or cache.
  • SQL injection or cache corruption.
  • Resource-limit bypass.

ConfigLedger is a static evidence tool, not a secret scanner or proof that a repository is secure.

There aren't any published security advisories