We take the security of Watercooler seriously. Please follow the process below when you believe you have found a vulnerability.
We aim to backport fixes to the latest minor release. During the 0.x series, we only patch the most recent tag.
- Email: security@watercoolerdev.com
- GPG: optional—include a link to your public key if you prefer encrypted responses.
Please include:
- A detailed description of the issue.
- Steps to reproduce, including sample configuration if possible.
- The impact you believe the issue could have.
We ask that you do not create public GitHub issues for suspected vulnerabilities.
- We will acknowledge receipt within 3 business days.
- We will work with you to reproduce the issue and determine severity.
- Fixes will be prepared privately. We target a public release within 30 days for high-severity issues (longer if coordination with downstream users is required).
- Once a fix is available, we will publish release notes and credit the reporter (unless you prefer to remain anonymous).
This policy covers the open-source watercooler codebase and official packages published by Mostly Harmless AI. Hosted services built on top of Watercooler may have additional policies documented separately.
Thank you for helping us keep Watercooler secure!