Skip to content

Security: mostlyharmless-ai/watercooler

Security

SECURITY.md

Security Policy

We take the security of Watercooler seriously. Please follow the process below when you believe you have found a vulnerability.

Supported Versions

We aim to backport fixes to the latest minor release. During the 0.x series, we only patch the most recent tag.

Reporting a Vulnerability

Please include:

  • A detailed description of the issue.
  • Steps to reproduce, including sample configuration if possible.
  • The impact you believe the issue could have.

We ask that you do not create public GitHub issues for suspected vulnerabilities.

Disclosure Timeline

  1. We will acknowledge receipt within 3 business days.
  2. We will work with you to reproduce the issue and determine severity.
  3. Fixes will be prepared privately. We target a public release within 30 days for high-severity issues (longer if coordination with downstream users is required).
  4. Once a fix is available, we will publish release notes and credit the reporter (unless you prefer to remain anonymous).

Scope

This policy covers the open-source watercooler codebase and official packages published by Mostly Harmless AI. Hosted services built on top of Watercooler may have additional policies documented separately.

Thank you for helping us keep Watercooler secure!

There aren't any published security advisories