Skip to content

Security: OpenCoven/sdk

SECURITY.md

Security policy

Supported versions

Before 1.0, security fixes target the latest pre-1.0 minor release. Older minor lines may require upgrading to receive a fix.

Reporting a vulnerability

Use GitHub private vulnerability reporting for suspected vulnerabilities in this repository. Do not open a public issue or discussion for an unresolved vulnerability.

Include:

  • impact and realistic attack conditions;
  • affected package and exact version;
  • a minimal reproduction;
  • known mitigations or workarounds.

Always redact credentials, tokens, payloads, private endpoint data, and raw SDK error causes. Provide only the minimum sensitive evidence required for triage.

Maintainers will assess scope and severity before agreeing on coordinated disclosure timing. No response-time or remediation SLA is promised.

There aren't any published security advisories