Skip to content

Security: tomevault-io/security-rules

SECURITY.md

Security policy

Reporting a vulnerability

Please report security problems privately, not in a public issue or pull request.

Use GitHub's private vulnerability reporting for this repository (you need to be signed in to GitHub): https://github.com/tomevault-io/security-rules/security/advisories/new

Include what you found, how to reproduce it, and what you think the impact is. We will acknowledge the report, keep you updated while we investigate, and credit you in the fix unless you ask us not to.

What belongs here and what belongs in an issue

Report privately: a way to write an instruction file that carries a credential leak, prompt injection, exfiltration or destructive command past these rules, when publishing it would help someone use the gap before it is closed.

Open a normal issue or RFC: false positives, missing coverage that is already publicly known, and proposals for new rules. Rule changes follow the process in RFC.md.

If the problem is in the TomeVault service at tomevault.io rather than in these rules, report it the same way here and say so.

Supported versions

Only the latest rule set version is supported.

There aren't any published security advisories