Skip to content

Security: TechSpokes/agents-feedback

Security

SECURITY.md

Security Policy

Supported Versions

Security fixes are prepared for the latest released version of agents-feedback.

Version Supported
1.x Yes

Reporting a Vulnerability

Report suspected vulnerabilities through GitHub private vulnerability reporting. If private vulnerability reporting is unavailable, contact the repository maintainer privately before opening a public issue.

Do not include secrets, credentials, raw private logs, customer data, private issue text, screenshots, large logs, or private tokens in public issues, discussions, pull requests, fixtures, examples, or documentation.

Include the affected version, a minimal reproduction, the expected impact, and any safe evidence that helps validate the report.

Public Discussion Boundary

Use the channels in SUPPORT.md for non-sensitive setup problems, documentation gaps, and feature requests. Use the private vulnerability path for anything that could affect repository integrity, release artifacts, agent instruction safety, or user data.

There aren't any published security advisories