Files
agent/SECURITY.md
Miles 4b935d97c8 docs: add private security disclosure policy
Add SECURITY.md and surface reporting guidance in README files.

Refs #256
2026-03-11 18:19:18 +08:00

1.2 KiB

Security Policy

Supported Versions

We only provide security fixes for the latest release series on the master branch.

Reporting a Vulnerability

Please do not open a public GitHub issue for potential security vulnerabilities.

Use one of the private channels below:

  1. Preferred: GitHub private vulnerability reporting
  2. Fallback: Email

Please include:

  • A short summary and impact.
  • Reproduction steps or proof of concept.
  • Affected version(s), commit hash, or deployment details.
  • Any proposed mitigation/workaround.
  • Your preferred attribution name.

For faster triage, use this subject format in email:

[Security][Kerberos Agent] <short title>

Response Expectations

  • Acknowledgement target: within 3 business days.
  • Triage/update target: within 7 business days after acknowledgement.

If you do not receive a response in time, please resend your report and include your original timestamp.

Disclosure and Credits

We follow coordinated disclosure. After a fix is available, we will credit reporters unless they prefer to stay anonymous.