Skip to content

Security: orange-dot/cooperations

SECURITY.md

Security Policy

Supported Versions

Only the latest main branch is supported for security fixes.

Reporting a Vulnerability

Please report security issues privately to the maintainers when possible.

Preferred options:

  1. Use a private security advisory channel if one is configured on the hosting platform.
  2. If no private channel is available, open a minimal public issue requesting a private follow-up and avoid sharing exploit details.

Scope

This project is a local-first workflow orchestration toolkit. Security concerns include:

  • secret handling and redaction
  • prompt-injection or untrusted input handling
  • local file access and write scope
  • logging, task history, and generated artifact storage

There aren’t any published security advisories