Skip to content

Security: codegeist-ai/.github

SECURITY.md

Security Policy

Supported Versions

Security support covers the latest main branch and current published releases. Older releases and unmerged branches may receive fixes only when maintainers determine that backporting is practical. Check the target repository's release notes for any more specific support policy.

Report Privately

Do not open a public Issue, pull request, task, roadmap item, or Discord message for a suspected vulnerability.

Use GitHub private vulnerability reporting in the affected repository when it is available. Otherwise, email dev@codegeist.ai with the affected repository, supported version or commit, impact, and minimal reproduction steps.

Never include credentials, access tokens, private keys, personal data, or sensitive configuration in any report. Use safe placeholders and redact logs, screenshots, and examples. Maintainers will arrange a safer exchange if more detail is necessary.

Response And Disclosure

Maintainers aim to acknowledge a report within three business days and provide an initial assessment or request for more information within seven business days. Complex reports may take longer; response times are targets, not guarantees.

Please allow time for validation and remediation. Coordinate public disclosure with maintainers so a fix, release, and advisory can be prepared before details are published. We will credit reporters who want attribution unless legal, privacy, or safety constraints prevent it.

Research Safety

Codegeist does not provide or guarantee a sandbox for security research. Do not test against production services, other users, third-party systems, or data you do not own. Use an isolated environment, stay within your authorization, avoid privacy violations and service disruption, and stop if testing could cause harm. Reporting a vulnerability does not grant authorization to access systems or data.

There aren't any published security advisories