Skip to content

Security: egohygiene/reflector

Security

SECURITY.md

Security Policy

reflector is an actively developed research repository. Security reports are still welcome, especially for issues involving automation, publication workflows, dependency handling, or generated artifacts.

Supported scope

Security reports should focus on the current default branch and the repository's published automation surfaces, including the CLI, scripts, and workflow configuration.

Reporting a vulnerability

Please do not disclose security issues publicly before coordination.

  1. Report the issue privately through GitHub's security reporting features when available.
  2. If private reporting is unavailable, contact the maintainer through GitHub before opening a public issue.
  3. Include reproduction steps, affected files or workflows, and the potential impact.

What to include

  • a concise description of the issue
  • steps to reproduce
  • impact and affected surfaces
  • suggested remediation, if known

There aren't any published security advisories