Skip to content

Security: xvyimu/Codexveil

Security

SECURITY.md

Security Policy

Supported versions

Security fixes are applied to the default branch of Codexveil on a best-effort basis.

Reporting a vulnerability

Please do not open a public issue for security reports.

  1. Prefer GitHub Security Advisories: repository → SecurityReport a vulnerability
  2. Or open a private channel via the maintainer account @xvyimu

We aim to acknowledge reports within 48 hours and share a remediation plan within 14 days for confirmed issues. High-severity issues are prioritized.

Scope notes

  • Do not include secrets, production credentials, or personal data in reports beyond what is needed to reproduce.
  • Out of scope: denial-of-service against third-party infrastructure, social engineering, physical attacks.

There aren't any published security advisories