Skip to content

Security: fellowship-dev/jev-second-brain

Security

SECURITY.md

Security policy

Supported versions

This project is pre-release. Until a tagged release exists, security fixes target the latest commit on main. Older commits and untagged snapshots are not maintained as separate supported versions.

Report a vulnerability

Use GitHub's private vulnerability reporting for this repository from the Security tab when it is available. Include the affected command or module, impact, reproduction steps using synthetic data, and any suggested mitigation.

If private reporting is unavailable, open a public issue containing only a request for a private maintainer contact. Do not include exploit details, private note content, credentials, provider responses, or state files in that issue.

The maintainer will confirm impact, coordinate a fix and disclosure, or explain why the report does not affect the project. Response timing depends on the report's scope and maintainer availability.

Sensitive material

If a credential was exposed, revoke or rotate it with its provider before reporting. If private notes or derived state were published, remove public access where possible and describe the affected data without copying it into the report.

There aren't any published security advisories