Skip to content

Security: SagaSmithAI/SagaSmith-Web

SECURITY.md

Security policy

Reporting a vulnerability

Do not open a public issue for a suspected vulnerability or include exploit details in a pull request. Use GitHub's private vulnerability reporting for this repository:

https://github.com/SagaSmithAI/SagaSmith-Web/security/advisories/new

Include the affected commit or deployment version, the impacted boundary, reproduction details, and the least-sensitive evidence that demonstrates the problem. Remove credentials, private campaign content, commercial source material, personal data, and provider responses from the report.

The maintainers will acknowledge a usable report, establish a private remediation path, and coordinate disclosure after supported deployments can be updated. Do not test against another person's campaign or a production deployment without explicit authorization.

Supported versions

SagaSmith Web is currently an active Alpha. Security fixes target the current default branch and the latest explicitly published release candidate. Older untagged snapshots are not supported.

There aren't any published security advisories