Early alpha — not recommended for production use yet.
Only the latest 0.1.0-alpha.* prerelease receives fixes. Pin to a released tag
and a published image digest for reproducibility.
Please do not open a public issue for security problems.
- Preferred: open a private GitHub Security Advisory.
- Or email the maintainer at o.guggenbuehl@gmail.com.
Include affected version/commit, impact, and reproduction steps. You'll get an acknowledgement as soon as possible; please allow reasonable time for a fix before public disclosure.
- The agent is designed to run fully contained (rootless, non-root, zero ambient credentials, secret-scrubbed telemetry) — see Sandboxing & YOLO Mode.
- CI runs secret scanning (gitleaks) and dependency/image vulnerability scanning (Trivy); never commit real credentials — the agent expects keys via CI secrets.