Skip to content

Security: bigg01/claude-ci-agent

Security

SECURITY.md

Security Policy

Early alpha — not recommended for production use yet.

Supported versions

Only the latest 0.1.0-alpha.* prerelease receives fixes. Pin to a released tag and a published image digest for reproducibility.

Reporting a vulnerability

Please do not open a public issue for security problems.

Include affected version/commit, impact, and reproduction steps. You'll get an acknowledgement as soon as possible; please allow reasonable time for a fix before public disclosure.

Notes

  • The agent is designed to run fully contained (rootless, non-root, zero ambient credentials, secret-scrubbed telemetry) — see Sandboxing & YOLO Mode.
  • CI runs secret scanning (gitleaks) and dependency/image vulnerability scanning (Trivy); never commit real credentials — the agent expects keys via CI secrets.

There aren't any published security advisories