Skip to content

Security: afri-bit/revibe

Security

SECURITY.md

Security policy

Revibe is a markdown-only repository. There is no server, dependency install step, or executable product shipped from this repo.

Reporting a concern

If you discover something sensitive (for example, accidentally committed secrets, or harmful instructions embedded in project documentation), please report it responsibly:

  1. Do not open a public issue for undisclosed sensitive details.
  2. Use GitHub private vulnerability reporting for this repository, or contact the maintainers of the afri-bit organization according to their published process.

Include enough context for maintainers to reproduce or verify the concern without exposing secrets in the report title.

What we do not treat as a “product vulnerability”

Typical items that are out of scope for classic CVE-style handling include:

  • Social engineering or misuse of AI tools by end users (Revibe is guidance, not executable code).
  • Issues in third-party tools (Copilot, Cursor, and so on); please report those to the respective vendors.

We still appreciate reports if documentation in this repo is misleading or could push learners toward unsafe practices—use issues for non-urgent documentation fixes.

There aren't any published security advisories