This document describes how to report security vulnerabilities in Ghostclaw and our policy for handling them.
We currently provide security updates for the following versions of Ghostclaw:
| Version | Supported |
|---|---|
| 0.2.x | ✅ |
| < 0.2.0 | ❌ |
Do NOT open a public issue for security-related reports.
We prioritize the privacy of our maintainers and reporters. To report a security vulnerability, please use GitHub's Private Vulnerability Reporting feature:
- Navigate to the Security tab of this repository.
- Select Advisories from the left-hand sidebar.
- Click Report a vulnerability to open a private advisory.
Using this method ensures the report remains confidential and allows us to collaborate on a fix securely.
When a vulnerability is reported through a private advisory:
- We will acknowledge the report within 48 hours.
- We will confirm the vulnerability and determine its severity.
- We will work on a fix in a private fork.
- Once fixed, we will publish the security advisory and release a new version of Ghostclaw.
Note
This policy helps protect the project and its users from premature disclosure. Thank you for your cooperation in keeping Ghostclaw secure!