Skip to content

Security: jbcom/agentic-fabric

SECURITY.md

Security policy

Reporting a vulnerability

Please use GitHub private vulnerability reporting for security-sensitive reports. Do not include credentials, exploit payloads, or sensitive details in public issues.

The supported release line is the latest published version of each package. We investigate reports affecting supported releases and coordinate disclosure through GitHub Security Advisories.

Supply-chain and contributor safety

This public repository treats fork pull requests, dependency updates, workflow changes, generated artifacts, caches, and documentation control files as untrusted. Pull-request CI has read-only permissions and no deployment or publication credentials. Releases publish through GitHub OIDC trusted publishing from trusted tags only.

There aren't any published security advisories