Skip to content

Security: opao-max/ChromeAI

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
latest main

Reporting a Vulnerability

If you discover a security vulnerability, please do not open a public issue.

Instead, use GitHub's private vulnerability reporting ("Report a vulnerability" on the Security tab), or contact the maintainer directly. Please include:

  • A description of the vulnerability and its impact
  • Steps to reproduce (proof-of-concept if possible)
  • Suggested remediation, if you have one

You should receive an acknowledgement within 72 hours. We will investigate, coordinate a fix, and credit the reporter in the advisory unless you prefer to remain anonymous.

Hardening Notes

  • Never commit secrets, API keys, or credentials; .env files are git-ignored.
  • Dependency updates are tracked by Dependabot; security advisories are addressed as a priority.
  • Continuous security analysis runs via GitHub CodeQL on every push.

There aren't any published security advisories