Security fixes are applied to the default branch of Codexveil on a best-effort basis.
Please do not open a public issue for security reports.
- Prefer GitHub Security Advisories: repository → Security → Report a vulnerability
- Or open a private channel via the maintainer account @xvyimu
We aim to acknowledge reports within 48 hours and share a remediation plan within 14 days for confirmed issues. High-severity issues are prioritized.
- Do not include secrets, production credentials, or personal data in reports beyond what is needed to reproduce.
- Out of scope: denial-of-service against third-party infrastructure, social engineering, physical attacks.