Skip to content

Security: Osraka/technocore-safe-agent

Security

SECURITY.md

Security Policy

Supported version

Until the first public release, only the current main branch is supported. After release, security fixes will target the latest published minor version.

Reporting a vulnerability

Use GitHub's private Report a vulnerability form when it is available for this repository. If private reporting is unavailable, contact the maintainer privately before sharing technical details. Do not open a public issue.

Include the affected version or commit, the smallest reproducible scenario, the expected security boundary, the observed behavior, and whether the test performed any live network or Keychain operation. Do not include private keys, seeds, room identifiers, message content, identity records, capability files, delivery journals, audit logs, or other user data.

Please avoid destructive testing, third-party accounts, automated scanning of live services, denial of service, and any attempt to extract data that is not your own. A report does not authorize testing against Technocore or GitHub.

There is no guaranteed response or remediation timeline during pre-release, but reports will be evaluated according to reproducibility and impact.

There aren't any published security advisories